Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5222

Опубликовано: 25 мая 2026
Источник: debian
EPSS Низкий

Описание

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cargoremovedpackage
cargono-dsabookwormpackage
cargopostponedbullseyepackage
rust-cargofixed0.91.0-3package
rust-cargono-dsatrixiepackage
rust-cargono-dsabookwormpackage
rust-cargopostponedbullseyepackage
rustcfixed1.95.0+dfsg1-2package
rustcno-dsatrixiepackage
rustcno-dsabookwormpackage
rustcpostponedbullseyepackage

Примечания

  • https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s

  • https://blog.rust-lang.org/2026/05/25/cve-2026-5222/

  • https://github.com/rust-lang/cargo/commit/c4d63a44234de22dc745231c416b80ed848d997f

EPSS

Процентиль: 31%
0.00379
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

CVSS3: 6.5
nvd
2 месяца назад

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

msrc
2 месяца назад

Cargo can be coerced to share credentials between registries

github
около 1 месяца назад

Cargo can be coerced to share credentials between registries

CVSS3: 6.5
fstec
2 месяца назад

Уязвимость менеджера пакетов Cargo языка программирования Rust, связанная с использованием неканонических URL-путей для решений авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 31%
0.00379
Низкий