Junglewise Threat Intelligence

Crossplane TOCTOU in signature verification bypass

Severity: medium · CVSS 4 · Published 2026-08-27

Technologies: Crossplane Runtime. Vendors: Crossplane.

Executive brief

Crossplane's package manager allows tag-based package installation to bypass cosign signature verification through a time-of-check-time-of-use race condition. A malicious OCI registry can serve a correctly signed image during verification, then swap it with an unsigned image during installation. This affects organizations that configure signature verification, use tag references for package installation, and pull packages from untrusted registries.

Technical details

The vulnerability is a TOCTOU race condition in xpkg.CachedClient where tag references are resolved separately during cosign signature verification and image fetch. An attacker controlling the OCI registry can serve a signed image for the verification step, then serve unsigned content when the resolved tag is fetched. This allows installation of unsigned packages when signature verification is enabled. The fix resolves the tag once to a digest and uses that digest for both verification and fetching.

Affected products

  • Crossplane crossplane-runtime 2.3.0 through 2.3.2, 2.4.0-rc.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in v2.3.3, v2.2.3, and v2.4.0-rc.1

References

Related threats