CVE detail
CVE-2026-5222
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
Information published.
vendormsrc.microsoft.comMay 27, 2026, 8:18 AM- Security Advisory for Cargo (CVE-2026-5222)Hacker News
Linked URL: https://blog.rust-lang.org/2026/05/25/cve-2026-5222/ | Posted by ingve | 3 points | 0 comments
communitynews.ycombinator.comMay 25, 2026, 8:08 PM No excerpt available.
Patchgroups.google.comMay 25, 2026, 10:16 AMNo excerpt available.
Exploitgithub.comMay 25, 2026, 10:16 AM- https://blog.rust-lang.org/2026/05/25/cve-2026-5222/blog.rust-lang.org
No excerpt available.
Vendor Advisoryblog.rust-lang.orgMay 25, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-62685CVSS 8.1 · High
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new…
- CVE-2026-8384CVSS 5.3 · Medium
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the exp…
- CVE-2026-59731CVSS 8.2 · High
Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit…
- CVE-2025-9909CVSS 6.7 · Medium
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes usin…
- CVE-2025-66202CVSS 6.5 · Medium
Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro…
- CVE-2025-64500CVSS 7.3 · High
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP…