# Crossplane v1.20.13

> Orchestration & Management · 2026-09-15

A security-focused maintenance release updates the Go toolchain and dependencies. It includes upstream vulnerability fixes, including a disclosed gRPC advisory.

## Action needed
- **[security · high]** `google.golang.org/grpc` update and GHSA-2v4p-qf9q-27wj fixes
  - The release updates `google.golang.org/grpc` to `v1.83.2` and includes a combined set of vulnerable dependency updates for upstream CVE fixes. This includes the gRPC advisory `GHSA-2v4p-qf9q-27wj`.
- **[security]** Go toolchain update to `1.26.7`
  - The release bumps the Go toolchain to `1.26.7`.

[Full analysis](https://ratatosk.io/en/releases/crossplane/v1.20.13)

[Original release notes](https://github.com/crossplane/crossplane/releases/tag/v1.20.13)
