Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5223

Опубликовано: 25 мая 2026
Источник: debian
EPSS Низкий

Описание

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cargoremovedpackage
cargono-dsabookwormpackage
cargopostponedbullseyepackage
rust-cargofixed0.91.0-3package
rust-cargono-dsatrixiepackage
rust-cargono-dsabookwormpackage
rust-cargopostponedbullseyepackage
rustcfixed1.95.0+dfsg1-2package
rustcno-dsatrixiepackage
rustcno-dsabookwormpackage
rustcpostponedbullseyepackage

Примечания

  • https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8

  • https://blog.rust-lang.org/2026/05/25/cve-2026-5223/

  • https://github.com/rust-lang/cargo/commit/285cebf58911eca5b7f177f5d0b1c53e1f646577

EPSS

Процентиль: 22%
0.00294
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
redhat
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
nvd
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

msrc
2 месяца назад

Crates in third party registries can override the cached source of other crates

github
около 1 месяца назад

Cargo crates in third party registries can override the cached source of other crates

EPSS

Процентиль: 22%
0.00294
Низкий