<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:21:30 +0000</lastBuildDate>
    <item>
      <title>BIT-crossplane-2023-38495 — Crossplane vulnerable to possible image tampering from missing image validation for Packages</title>
      <link>https://cve.radiocsirt.org/vuln/bit-crossplane-2023-38495</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: crossplane&lt;/p&gt;
&lt;p&gt;Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane&amp;#39;s image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: crossplane&lt;/p&gt;
&lt;p&gt;Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane&amp;#39;s image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-crossplane-2023-38495</guid>
    </item>
    <item>
      <title>EUVD-2026-194786</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-194786</link>
      <description>EUVD-2026-194786</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-194786</guid>
    </item>
    <item>
      <title>fkie_cve-2023-38495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-38495</link>
      <description>&lt;p&gt;Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane&amp;#39;s image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane&amp;#39;s image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0. As a workaround, only use images from trusted sources and keep Package editing/creating privileges to administrators only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-38495</guid>
    </item>
    <item>
      <title>GHSA-pj4x-2xr5-w87m — Possible image tampering from missing image validation for Packages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pj4x-2xr5-w87m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/crossplane/crossplane&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Crossplanes image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0, all the supported versions of Crossplane at the time of writing.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Only using images from trusted sources and keeping Package editing/creating privileges to administrators only, which should be both considered already best practices.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;See `ADA-XP-23-11` in the Security Audit&amp;#39;s [report](https://github.com/crossplane/crossplane/blob/ac8b24fe739c5d942ea885157148497f196c3dd3/security/ADA-security-audit-23.pdf).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This was reported as `ADA-XP-23-11` by @AdamKorcz and @DavidKorczynski from Ada Logic and facilitated by OSTIF as part of the Security Audit sponsored by CNCF.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/crossplane/crossplane&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Crossplanes image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been fixed in 1.11.5, 1.12.3 and 1.13.0, all the supported versions of Crossplane at the time of writing.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Only using images from trusted sources and keeping Package editing/creating privileges to administrators only, which should be both considered already best practices.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;See `ADA-XP-23-11` in the Security Audit&amp;#39;s [report](https://github.com/crossplane/crossplane/blob/ac8b24fe739c5d942ea885157148497f196c3dd3/security/ADA-security-audit-23.pdf).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;This was reported as `ADA-XP-23-11` by @AdamKorcz and @DavidKorczynski from Ada Logic and facilitated by OSTIF as part of the Security Audit sponsored by CNCF.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pj4x-2xr5-w87m</guid>
    </item>
    <item>
      <title>gsd-2023-38495</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-38495</link>
      <description>gsd-2023-38495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-38495</guid>
    </item>
  </channel>
</rss>
