Sceawere
Vulnerability Detail
CVE-2026-105163UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Crossplane-runtime TOCTOU Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 20h ago
- Vendor
- crossplane
- Product
- crossplane-runtime
- Attack Type
- Time-of-check Time-of-use
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and 2.4.0-rc.1 is able to resolve this issue. The patch is identified as bee99c6cd6ca81878acca2940a2f0a02169fc208. You should upgrade the affected component.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-04T22:16:58.763Z",
"pubdate": "2026-10-04T22:16:58.763Z",
"executiveSummary": "A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability has been identified within the crossplane-runtime component of Crossplane.\nThe vulnerability resides in the ImageConfig module specifically within the Get function located in pkg/xpkg/client.go.\nThis flaw potentially allows a remote attacker to exploit the gap between the validation of a resource state and its subsequent usage, leading to unauthorized state manipulation or bypasses.\nThe vulnerability affects crossplane-runtime versions up to 2.2.2 and 2.3.2.\nSuccessful exploitation could allow an attacker to influence system operations in ways not intended by the initial configuration check.\nImmediate remediation involves upgrading the affected package to secure versions 2.2.3, 2.3.3, or 2.4.0-rc.1 to eliminate the race condition.",
"technicalDetails": "The vulnerability is a classic race condition known as Time-of-Check Time-of-Use (TOCTOU). It occurs within the pkg/xpkg/client.go file of the ImageConfig component when utilizing the Get function.\nIn a TOCTOU scenario, the software performs a check on a resource—in this instance, likely an image configuration—to ensure it satisfies specific security or functional criteria. However, because the system does not maintain atomicity between this check and the subsequent operation (the 'use'), an attacker can modify the underlying resource during the intervening window.\nThe attack flow involves an attacker monitoring the execution of the Get function. By inducing a state change in the target resource precisely after the validation check has completed but before the execution phase has initiated, the attacker can cause the component to process malicious or unauthorized data that would have otherwise been rejected during the check phase.\nBecause the vulnerability is remotely exploitable, an attacker does not require local access to the host machine. They can influence the environment remotely to trigger the race condition, potentially leading to unauthorized configuration application or the bypass of security constraints intended to gatekeep resource retrieval or deployment.\nThe root cause is the lack of proper synchronization or locking mechanisms within the Get function, which allows for concurrent modifications to the target configuration state. The specific patch, identified as bee99c6cd6ca81878acca2940a2f0a02169fc208, addresses this by ensuring that the object retrieved and validated is protected from external tampering until the operation is completed.\nThe exploitation of this flaw does not necessarily require complex privileges if the service is exposed, as the race condition is inherent in the logic of the code rather than an authentication bypass. Once the TOCTOU window is hit, the post-exploitation impact could include the deployment of unauthorized images, misconfiguration of infrastructure components, or other actions that subvert the intended operational integrity of the Crossplane runtime."
}