CVE-2026-5222
published 2026-05-25CVE-2026-5222: Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple…
PriorityP341medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.33%
25.1th percentile
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rust-lang | cargo | >= 1.68.0 < 1.96.0 | 1.96.0 |
| rust | cargo | >= 0 < 0.97.0 | 0.97.0 |
| rust | cargo | >= 1.68.0 < 1.96.0 | 1.96.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cvelistv5v4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
ghsa6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cargo can be coerced to share credentials between registries
ghsa·2026-06-26·CVSS 6.5
CVE-2026-5222 [MEDIUM] CWE-647 Cargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
The Rust Security Response Team was notified that Cargo incorrectly normalized the URLs of third-party registries using the [sparse index protocol][1]. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry.
This vulnerability is tracked as CVE-2026-5222. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
## Overview
Originally Cargo only supported storing a registry's index within git repositories. Most git hosting solutions allow accessing a git repository with or without the `.git` suffix, so C
CVEList
Cargo can be coerced to share credentials between registries
cvelistv5·2026-05-25·CVSS 2.3
CVE-2026-5222 [LOW] CWE-647 Cargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
VulDB
rust-lang Cargo up to 1.95.x non-canonical url paths for authorization decisions (EUVD-2026-31654)
vuldb·2026-05-25
CVE-2026-5222 [LOW] rust-lang Cargo up to 1.95.x non-canonical url paths for authorization decisions (EUVD-2026-31654)
A vulnerability was found in rust-lang Cargo up to 1.95.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to use of non-canonical url paths for authorization decisions.
This vulnerability appears as CVE-2026-5222. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [epel-all]
bugzilla·2026-06-17·CVSS 6.5
CVE-2026-5222 [MEDIUM] CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [epel-all]
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [fedora-all]
bugzilla·2026-06-17·CVSS 6.5
CVE-2026-5222 [MEDIUM] CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [fedora-all]
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw
bugzilla·2026-05-25·CVSS 6.5
CVE-2026-5222 [MEDIUM] CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw
CVE-2026-5222 rust-cargo: rust-cargo: Information disclosure due to URL normalization flaw
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
Bugzilla
CVE-2025-5222 icu: Stack buffer overflow in the SRBRoot::addTag function [fedora-42]
bugzilla·2025-05-26·CVSS 7.0
CVE-2025-5222 [HIGH] CVE-2025-5222 icu: Stack buffer overflow in the SRBRoot::addTag function [fedora-42]
CVE-2025-5222 icu: Stack buffer overflow in the SRBRoot::addTag function [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2368600
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Pac
2026-05-25
Published