CVE-2026-105163 | crossplane crossplane-runtime up to 2.2.2/2.3.2 ImageConfig pkg/xpkg/client.go Get toctou (GHSA-mf7q-r4rv-jv94)

SecurityVulns

A vulnerability, which was classified as problematic, was found in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use.

This vulnerability is cataloged as CVE-2026-105163. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More