Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-5223

Опубликовано: 27 мая 2026
Источник: msrc
EPSS Низкий

Описание

Crates in third party registries can override the cached source of other crates

EPSS

Процентиль: 22%
0.00294
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
redhat
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
nvd
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
debian
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded ...

github
около 1 месяца назад

Cargo crates in third party registries can override the cached source of other crates

EPSS

Процентиль: 22%
0.00294
Низкий