Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component. | |
| Title | crossplane crossplane-runtime ImageConfig client.go Get toctou | |
| First Time appeared |
Crossplane
Crossplane crossplane-runtime |
|
| Weaknesses | CWE-362 CWE-367 |
|
| CPEs | cpe:2.3:a:crossplane:crossplane-runtime:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Crossplane
Crossplane crossplane-runtime |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-04T21:30:12.785Z
Reserved: 2026-10-04T07:28:17.729Z
Link: CVE-2026-105163
No data.
Status : Received
Published: 2026-10-04T22:16:58.763
Modified: 2026-10-04T22:16:58.763
Link: CVE-2026-105163
No data.
OpenCVE Enrichment
Updated: 2026-10-04T22:30:08Z