CVE-2026-5223

Name
CVE-2026-5223
Description
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
986d4109-89ea-491f-99fd-a8e4803919bd https://blog.rust-lang.org/2026/05/25/cve-2026-5223/
986d4109-89ea-491f-99fd-a8e4803919bd https://github.com/rust-lang/cargo/pull/17031
986d4109-89ea-491f-99fd-a8e4803919bd https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:* cargo >= None < 1.96.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
rust edge-main 1.96.0-r0 team/rust <alpine@ptrcnull.me> fixed
rust 3.24-main 1.96.0-r0 team/rust <alpine@ptrcnull.me> fixed
rust 3.23-main 1.91.1-r2 team/rust <alpine@ptrcnull.me> fixed