Description
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Sun, 04 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Title crossplane crossplane-runtime ImageConfig client.go Get toctou
First Time appeared Crossplane
Crossplane crossplane-runtime
Weaknesses CWE-362
CWE-367
CPEs cpe:2.3:a:crossplane:crossplane-runtime:*:*:*:*:*:*:*:*
Vendors & Products Crossplane
Crossplane crossplane-runtime
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Crossplane Crossplane-runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T15:11:53.371Z

Reserved: 2026-10-04T07:28:17.729Z

Link: CVE-2026-105163

cve-icon Vulnrichment

Updated: 2026-10-05T15:11:50.216Z

cve-icon NVD

Status : Deferred

Published: 2026-10-04T22:16:58.763

Modified: 2026-10-06T15:04:52.637

Link: CVE-2026-105163

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-04T21:30:12Z

Links: CVE-2026-105163 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T00:00:13Z

Weaknesses