216.73.217.22

CVE-2026-5222

· Published 25/05/2026 10:16 · Modified 26/05/2026 19:08

Labels: CVE-2026-5222 2026-05-25986d4109-89ea-491f-99fd-a8e4803919bdCVE-2026-5222CWE-647

Essential information

Published
25/05/2026 10:16
Modified
26/05/2026 19:08
Author
Creator
CVSS
2.3 LOW (v3) 2.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
986d4109-89ea-491f-99fd-a8e4803919bd
NVD
View on NVD

Affected products (CPE)

ProductCPE
rust-lang / cargo cpe:2.3:a:rust-lang:cargo:1.68-1.96:*:*:*:*:*:*:*

References