Description
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote code execution via TOCTOU race condition
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a time‑of‑check/time‑of‑use race condition in the ImageConfig Get function of crossplane‑runtime. An attacker can manipulate the state between the check and the use of an image configuration, potentially allowing unauthorized manipulation of deployment details or execution of code with the privileges of the service. This flaw is classified under CWE‑362 and CWE‑367. The flaw can be exploited over the network, giving an attacker a remote entry point into the system.

Affected Systems

The issue affects crossplane crossplane‑runtime versions up to 2.2.2 and 2.3.2. Updating to 2.2.3, 2.3.3 or the 2.4.0‑rc.1 release removes the bug.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating moderate severity, and the EPSS score is unavailable, suggesting no current public exploitation data. It is not listed in the CISA KEV catalog. Because the failure is a race condition that can be triggered remotely, the risk is that a remote attacker can manipulate image configuration handling, leading to potential privilege escalation or code execution. The lack of known exploitation does not reduce the importance of patching, as the underlying race condition remains exploitable by a determined adversary.

Generated by OpenCVE AI on October 4, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade crossplane‑runtime to v2.2.3, v2.3.3, or v2.4.0‑rc.1 to apply the fix identified by commit bee99c6cd6ca81878acca2940a2f0a02169fc208.
  • Where upgrading is delayed, restrict network access to the Crossplane API endpoints that invoke the ImageConfig Get function, reducing the window for an attacker to trigger the race condition.
  • Implement monitoring for unexpected changes to image configuration objects and enforce strict validation of image references to mitigate potential misuse of the race condition until a patch is available.

Generated by OpenCVE AI on October 4, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Title crossplane crossplane-runtime ImageConfig client.go Get toctou
First Time appeared Crossplane
Crossplane crossplane-runtime
Weaknesses CWE-362
CWE-367
CPEs cpe:2.3:a:crossplane:crossplane-runtime:*:*:*:*:*:*:*:*
Vendors & Products Crossplane
Crossplane crossplane-runtime
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Crossplane Crossplane-runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T21:30:12.785Z

Reserved: 2026-10-04T07:28:17.729Z

Link: CVE-2026-105163

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T22:16:58.763

Modified: 2026-10-04T22:16:58.763

Link: CVE-2026-105163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T22:30:08Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition