CVE-2026-5222

Name
CVE-2026-5222
Description
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
986d4109-89ea-491f-99fd-a8e4803919bd https://blog.rust-lang.org/2026/05/25/cve-2026-5222/
986d4109-89ea-491f-99fd-a8e4803919bd https://github.com/rust-lang/cargo/pull/17031
986d4109-89ea-491f-99fd-a8e4803919bd https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:* cargo >= 1.68.0 < 1.96.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
rust edge-main 1.96.0-r0 team/rust <alpine@ptrcnull.me> fixed
rust 3.24-main 1.96.0-r0 team/rust <alpine@ptrcnull.me> fixed
rust 3.23-main 1.91.1-r2 team/rust <alpine@ptrcnull.me> fixed