Описание
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cargo | removed | package | ||
| cargo | no-dsa | bookworm | package | |
| cargo | postponed | bullseye | package | |
| rust-cargo | fixed | 0.91.0-3 | package | |
| rust-cargo | no-dsa | trixie | package | |
| rust-cargo | no-dsa | bookworm | package | |
| rust-cargo | postponed | bullseye | package | |
| rustc | fixed | 1.95.0+dfsg1-2 | package | |
| rustc | no-dsa | trixie | package | |
| rustc | no-dsa | bookworm | package | |
| rustc | postponed | bullseye | package |
Примечания
https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s
https://blog.rust-lang.org/2026/05/25/cve-2026-5222/
https://github.com/rust-lang/cargo/commit/c4d63a44234de22dc745231c416b80ed848d997f
EPSS
Связанные уязвимости
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Cargo can be coerced to share credentials between registries
Уязвимость менеджера пакетов Cargo языка программирования Rust, связанная с использованием неканонических URL-путей для решений авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS