CVE-2026-5222General(rust-lang / cargo)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch rust-lang cargo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-647

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cargo

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
cargo

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-25: 3Mentions · 2026-05-29: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-05-25: 205-2505-2906-02
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-253
Disclosure1General1Patch1
2026-05-291
General1
2026-06-021
Patch1
Full discourse5 posts
  • Rust Bytes 🦀@rustaceans_rs
    Patch

    JUST IN: Security Advisory for Cargo (CVE-2026-5222) >> Cargo CVE-2026-5222: Sparse registry URL normalization flaw lets attackers steal credentials from third-party registries under niche conditions. Fixed in Rust 1.96. #rustlang #rustlang https://t.co/xCBqWItgGX

    Post summary

    The tweet announces a security advisory for CVE‑2026‑5222, highlighting a registry URL normalization flaw that could allow credential theft and noting a fix in Rust 1.96.

    1101221.0K
    6.0K followersView on X
  • Open Source Security mailing list@oss_security
    General

    Cargo from Rust security advisories https://www.openwall.com/lists/oss-security/2026/05/28/5 CVE-2026-5222: Cargo can be coerced to share credentials between registries CVE-2026-5223: Crates in third party registries can override the cached source of other crates

    Post summary

    The text announces two new Rust Cargo CVEs with brief descriptions, but it contains no proof of concepts, exploit code, active exploitation reports, patches, or technical details.

    01041384
    4.7K followersView on X
  • Rust Bytes 🦀@rustaceans_rs
    General

    Link: https://blog.rust-lang.org/2026/05/25/cve-2026-5222/

    Post summary

    The content only supplies a URL to a Rust blog post, with no explicit details about exploitation, patches, or technical aspects of the CVE.

    00021324
    6.0K followersView on X
  • Mike Tang@daogangtang
    Patch

    🦀 Rust Daily Digest — June 1, 2026 Rust 1.96.0 stable (Copy Range types + assert_matches!), Cargo CVE-2026-5222/5223 patched, 1.97.0 enters beta, HN on Rust kernel features, AI tools halving Rust onboarding time, WhatsApp zero memory-safety CVEs at global scale. https://x.com/daogangtang/status/2061631035927113948

    Post summary

    The digest reports that Rust 1.96.0 has patched CVE‑2026‑5222 and CVE‑2026‑5223, with no evidence of exploits or PoCs shared.

    0001060
    573 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5222 Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries… https://www.cve.org/CVERecord?id=CVE-2026-5222

    Post summary

    The text announces CVE-2026-5222, a URL normalization issue in Cargo 1.68‑1.96 affecting third‑party registries via the sparse index protocol.

    00000220
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprust-langcargo-rust-

Explore more