Количество 7
Количество 7
GHSA-jq42-7mfv-hm57
Cargo crates in third party registries can override the cached source of other crates
CVE-2026-5223
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
CVE-2026-5223
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
CVE-2026-5223
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
CVE-2026-5223
Crates in third party registries can override the cached source of other crates
CVE-2026-5223
Cargo incorrectly handled symlinks inside of crate tarballs downloaded ...
BDU:2026-08152
Уязвимость менеджера пакетов Cargo языка программирования Rust, связанная с недостатками механизма обработки символьных ссылок, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-jq42-7mfv-hm57 Cargo crates in third party registries can override the cached source of other crates | 0% Низкий | около 1 месяца назад | ||
CVE-2026-5223 Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5223 Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5223 Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5223 Crates in third party registries can override the cached source of other crates | 0% Низкий | 2 месяца назад | ||
CVE-2026-5223 Cargo incorrectly handled symlinks inside of crate tarballs downloaded ... | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
BDU:2026-08152 Уязвимость менеджера пакетов Cargo языка программирования Rust, связанная с недостатками механизма обработки символьных ссылок, позволяющая нарушителю выполнить произвольный код | CVSS3: 5.3 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу