Skip to main content

Vendor/product archive

rust-lang / cargo CVEs

Beta · best-effort

6 CVEs tagged to rust-lang / cargo0 Critical, 1 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-5223

Published May 25, 2026

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from th…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-5222

Published May 25, 2026

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be host…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2022-46176

Published Jan 11, 2023

Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36114

Published Sep 14, 2022

Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could u…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36113

Published Sep 14, 2022

Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1