Medium severity6.5NVD Advisory· Published May 25, 2026· Updated Jul 23, 2026
CVE-2026-5222
CVE-2026-5222
Description
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is low, due to the extremely niche requirements needed to achieve the attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cargocrates.io | < 0.97.0 | 0.97.0 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/rust-lang/cargo/pull/17031nvdIssue TrackingPatchWEB
- blog.rust-lang.org/2026/05/25/cve-2026-5222/nvdVendor Advisory
- github.com/advisories/GHSA-p688-r7jv-fm6fghsaADVISORY
- groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5snvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-5222ghsaADVISORY
- blog.rust-lang.org/2026/05/25/cve-2026-5222ghsaWEB
- github.com/rust-lang/cargo/security/advisories/GHSA-p688-r7jv-fm6fghsaWEB
News mentions
0No linked articles in our index yet.