CVE-2026-105163: crossplane crossplane-runtime ImageConfig client.go Get toctou
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
crossplane/crossplane-runtimeto a version that resolves this vulnerability.Patch bee99c6cd6ca81878acca2940a2f0a02169fc208
Event History
Frequently Asked Questions
Which releases should be upgraded?
crossplane-runtime versions up to 2.2.2 and 2.3.2 are affected. Upgrade to 2.2.3, 2.3.3, or 2.4.0-rc.1.
Does exploitation require authentication or user interaction?
No authentication or user interaction is required according to the supplied CVSS vector. The attack can be launched remotely and has low attack complexity.
What security impact is reported?
The reported impact is integrity-only: an attacker may cause an unauthorized modification. No confidentiality or availability impact is reported.
How can I identify the remediation patch?
The patch is identified as commit bee99c6cd6ca81878acca2940a2f0a02169fc208. Verify that your deployed source or package includes this change, or move to one of the listed fixed releases.