Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. cargo
  4. ›
  5. CVE-2026-5222

CVE-2026-5222: Cargo can be coerced to share credentials between registries

June 26, 2026

The Rust Security Response Team was notified that Cargo incorrectly normalized the URLs of third-party registries using the [sparse index protocol][1]. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry.

This vulnerability is tracked as CVE-2026-5222. The severity of the vulnerability is low, due to the extremely niche requirements needed to achieve the attack.

References

  • blog.rust-lang.org/2026/05/25/cve-2026-5222
  • github.com/advisories/GHSA-p688-r7jv-fm6f
  • github.com/rust-lang/cargo/pull/17031
  • github.com/rust-lang/cargo/security/advisories/GHSA-p688-r7jv-fm6f
  • groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s
  • nvd.nist.gov/vuln/detail/CVE-2026-5222

Code Behaviors & Features

Detect and mitigate CVE-2026-5222 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.97.0

Fixed versions

  • 0.97.0

Solution

Upgrade to version 0.97.0 or above.

Impact 4.7 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-647: Use of Non-Canonical URL Paths for Authorization Decisions

Source file

cargo/cargo/CVE-2026-5222.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 12:16:31 +0000.