{"id":"CVE-2026-105163","title":"A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2","summary":"A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-u…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-362","CWE-367"],"vendor":"crossplane","product":"crossplane-runtime","affected":["crossplane-runtime 2.2.0","crossplane-runtime 2.2.1","crossplane-runtime 2.2.2","crossplane-runtime 2.3.0","crossplane-runtime 2.3.1","crossplane-runtime 2.3.2"],"published":"2026-10-04","updated":"2026-10-04","sourceUpdated":"2026-10-04T22:16:58.763","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105163","references":[{"url":"https://github.com/advisories/GHSA-mf7q-r4rv-jv94","label":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/","label":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/commit/bee99c6cd6ca81878acca2940a2f0a02169fc208","label":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/pull/1038","label":"cna@vuldb.com"},{"url":"https://github.com/crossplane/crossplane-runtime/releases/tag/v2.2.3","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105163","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413395/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-04T22:04:19.354Z","slug":"CVE-2026-105163","body":"## Overview\n\nA vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}