# Crossplane v2.4.1

> Orchestration & Management · 2026-09-15

A maintenance release with a package-revision handoff fix and dependency security updates. It includes the gRPC advisory `GHSA-2v4p-qf9q-27wj` and refreshes the Go toolchain and related dependencies.

## Action needed
- **[security · high]** `google.golang.org/grpc` update for `GHSA-2v4p-qf9q-27wj`
  - `google.golang.org/grpc` is updated to `v1.83.2` to pick up upstream fixes, including advisory `GHSA-2v4p-qf9q-27wj`. The update ships with the release's dependency security refresh.
- **[security]** The Go toolchain update
  - The Go toolchain is updated to `1.26.7` as part of the dependency security updates. The release also updates `google.golang.org/grpc` to `v1.83.2`, `golang.org/x/crypto` to `v0.56.0`, `github.com/crossplane/crossplane/apis/v2` to `v2.4.0`, and refreshes the lock file.
- **[security]** `golang.org/x/crypto` update
  - `golang.org/x/crypto` is updated to `v0.56.0` as part of the dependency security updates. The same refresh updates the Go toolchain to `1.26.7`, `google.golang.org/grpc` to `v1.83.2`, and refreshes the lock file.

## Other recorded changes
- 2 (value_changed 1, defect_corrected 1)

[Full analysis](https://ratatosk.io/en/releases/crossplane/v2.4.1)

[Original release notes](https://github.com/crossplane/crossplane/releases/tag/v2.4.1)
