PT-2026-104649 · Crossplane · Crossplane-Runtime

·

CVE-2026-105163

·

Published

2026-08-27

·

Updated

2026-10-04

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions crossplane crossplane-runtime versions 2.2.0 through 2.2.2 crossplane crossplane-runtime versions 2.3.0 through 2.3.2
Description A time-of-check time-of-use (TOCTOU) issue exists in the ImageConfig component within the Get() function of the pkg/xpkg/client.go file. This occurs when package signature verification is enabled and packages are installed using tag references instead of digests from registries not controlled by the user. A malicious OCI registry could provide a correctly signed image during the verification step and subsequently serve an unsigned or malicious image during the installation step because the tag reference is resolved separately for each action. This allows for the remote installation of unverified package content.
Recommendations Update crossplane crossplane-runtime versions 2.2.0 through 2.2.2 to version 2.2.3. Update crossplane crossplane-runtime versions 2.3.0 through 2.3.2 to version 2.3.3. Install packages by image digest rather than using tags to avoid this issue.

Exploit

Fix

Time Of Check To Time Of Use

Race Condition

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105163
GHSA-MF7Q-R4RV-JV94
GO-2026-6302

Affected Products

Crossplane-Runtime