blog.rust-lang.orgVendor advisory
https://blog.rust-lang.org/2026/05/25/cve-2026-5222 CVE-2026-5222
LOW
Cargo can be coerced to share credentials between registries
Record summary
CVE-2026-5222 has a selected CVSS score of 2.3 (low).
Description
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
CargoBrowse Rust / CargoDefault status: unaffected | CVE List | 1.68.0 to < 1.96.0 | affected |
| GitHub Advisory | Before 0.97.0 · Fixed in 0.97.0 | affected |
References
6github.com
https://github.com/rust-lang/cargo github.compatch
https://github.com/rust-lang/cargo/pull/17031 github.com
https://github.com/rust-lang/cargo/security/advisories/GHSA-p688-r7jv-fm6f groups.google.comVendor advisorymailing list
https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5222