Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5222

Опубликовано: 25 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is low, due to the extremely niche requirements needed to achieve the attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:*
Версия от 1.68.0 (включая) до 1.96.0 (исключая)

EPSS

Процентиль: 31%
0.00379
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-647

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

msrc
2 месяца назад

Cargo can be coerced to share credentials between registries

CVSS3: 6.5
debian
2 месяца назад

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-p ...

github
около 1 месяца назад

Cargo can be coerced to share credentials between registries

CVSS3: 6.5
fstec
2 месяца назад

Уязвимость менеджера пакетов Cargo языка программирования Rust, связанная с использованием неканонических URL-путей для решений авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 31%
0.00379
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-647