PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5222 Rust CVE debrief

CVE-2026-5222 is a low-severity vulnerability in Cargo, the Rust package manager, affecting versions 1.68 through 1.96. The issue stems from incorrect URL normalization when Cargo interacts with third-party registries using the sparse index protocol. Specifically, if a hosting provider allows multiple registries to be hosted with arbitrary names within the same domain, an attacker with the ability to publish crates in one registry could potentially obtain credentials of other users of that same registry. The attack requires extremely niche conditions: a hosting provider must allow arbitrary registry names within a shared domain, and the attacker must have publishing privileges. The vulnerability was disclosed by the Rust Security Response WG on May 25, 2026, with a fix implemented in Cargo pull request 17031. Users should upgrade to Cargo 1.97 or later to remediate this issue.

Vendor
Rust
Product
Cargo
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-07-23
Advisory published
2026-05-25
Advisory updated
2026-07-23

Who should care

Organizations operating private Cargo registries on hosting providers that allow arbitrary registry naming within shared domains; Rust developers using third-party registries with sparse index protocol; security teams monitoring supply chain integrity for Rust ecosystems.

Technical summary

Affected versions of Cargo (1.68-1.96) normalize URLs for third-party registries using the sparse index protocol without properly accounting for registry name boundaries within a domain. When a hosting provider permits arbitrary registry names under a single domain, Cargo's normalization logic can conflate different registries, causing credentials intended for one registry to be sent to another. An attacker with publish access to a maliciously-named registry could exploit this to harvest credentials from legitimate users. The CVSS 4.0 vector indicates network attack vector, low attack complexity, privileged attack requirements, and user interaction needed, with low confidentiality impact to the victim and low subsequent confidentiality impact to the system.

Defensive priority

low

Recommended defensive actions

  • Upgrade Cargo to version 1.97 or later to obtain the fix for incorrect URL normalization in sparse index registry handling.
  • Review hosting configurations for private Cargo registries to ensure registry names are not arbitrarily assignable within shared domains.
  • Audit registry access logs for any anomalous credential usage patterns if running affected Cargo versions with third-party registries.

Evidence notes

The CVE description explicitly states severity is low due to extremely niche requirements. The Rust Security Response WG published the advisory on 2026-05-25 per the official blog post. The fix is documented in GitHub pull request 17031.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5222 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5222

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5222 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5222

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://blog.rust-lang.org/2026/05/25/cve-2026-5222/

    986d4109-89ea-491f-99fd-a8e4803919bd

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rust-lang/cargo/pull/17031

    986d4109-89ea-491f-99fd-a8e4803919bd

  • Source reference

    Unverified legacy reference

    URL: https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s

    986d4109-89ea-491f-99fd-a8e4803919bd

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.