Executive brief
Crossplane's package manager allows tag-based package installation to bypass cosign signature verification through a time-of-check-time-of-use race condition. A malicious OCI registry can serve a correctly signed image during verification, then swap it with an unsigned image during installation. This affects organizations that configure signature verification, use tag references for package installation, and pull packages from untrusted registries.
Technical details
The vulnerability is a TOCTOU race condition in xpkg.CachedClient where tag references are resolved separately during cosign signature verification and image fetch. An attacker controlling the OCI registry can serve a signed image for the verification step, then serve unsigned content when the resolved tag is fetched. This allows installation of unsigned packages when signature verification is enabled. The fix resolves the tag once to a digest and uses that digest for both verification and fetching.
Affected products
- Crossplane crossplane-runtime 2.3.0 through 2.3.2, 2.4.0-rc.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in v2.3.3, v2.2.3, and v2.4.0-rc.1