← Back to CVE List
CVE-2026-105163NVD
Vulnerability Summary
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- crossplane crossplane-runtime >= 2.2.0
- crossplane crossplane-runtime >= 2.2.1
- crossplane crossplane-runtime >= 2.2.2
- crossplane crossplane-runtime >= 2.3.0
- crossplane crossplane-runtime >= 2.3.1
- crossplane crossplane-runtime >= 2.3.2
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413395
- https://vuldb.com/vuln/413395/cti
- https://vuldb.com/cve/CVE-2026-105163
- https://github.com/advisories/GHSA-mf7q-r4rv-jv94
- https://github.com/crossplane/crossplane-runtime/pull/1038
- https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208
- https://github.com/crossplane/crossplane-runtime/releases/tag/v2.2.3
- https://github.com/crossplane/crossplane-runtime/