← Back

CVE-2026-5222

nvd nist
Published: May 25, 2026Modified: Jul 23, 2026

JSON object

Loading...
2.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 986d4109-89ea-491f-99fd-a8e4803919bd (Secondary)

Description

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

Affected (1)

Products: Rust Lang: Cargo
1 product
Cargo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.68.0 to 1.96.0

References (3)

Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Vendor Advisory
Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Issue TrackingPatch
Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Mailing ListThird Party Advisory

Timeline

No history available yet.