216.73.217.22

CVE-2026-5223

· Published 25/05/2026 10:16 · Modified 26/05/2026 19:08

Labels: CVE-2026-5223 2026-05-25986d4109-89ea-491f-99fd-a8e4803919bdCVE-2026-5223CWE-61

Essential information

Published
25/05/2026 10:16
Modified
26/05/2026 19:08
Author
Creator
CVSS
6.5 MEDIUM (v3) 6.5 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
986d4109-89ea-491f-99fd-a8e4803919bd
NVD
View on NVD

Affected products (CPE)

ProductCPE
cargo / cargo cpe:2.3:a:cargo:cargo:*:*:*:*:*:*:*:*

References