CVE-2026-5222: Rust-Lang Cargo
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Affected products
- Rust-Lang Cargo: from 1.68.0, before 1.96.0 (fixed in 1.96.0)
Published 2026-05-25. Last modified 2026-07-23.