CVE-2026-5222

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:*

History

No history.

Information

Published : 2026-05-25 10:16

Updated : 2026-07-23 17:10


NVD link : CVE-2026-5222

Mitre link : CVE-2026-5222

CVE.ORG link : CVE-2026-5222


JSON object : View

Products Affected

rust-lang

  • cargo
CWE
CWE-647

Use of Non-Canonical URL Paths for Authorization Decisions