PT-2026-43024 · Rust · Cargo
Christos Papakonstantinou
·
Published
2026-05-25
·
Updated
2026-06-02
·
CVE-2026-5222
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cargo versions 1.68 through 1.95
Description
Cargo incorrectly normalized URLs of third-party registries using the sparse index protocol. In scenarios where a hosting provider allows multiple registries to be hosted with arbitrary names within the same domain, an attacker capable of publishing crates in a registry could obtain the credentials of other users of that same registry.
Recommendations
Update to version 1.96.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cargo