Security Advisory for Cargo (CVE-2026-5222)

44 · The Rust Programming Language · May 25, 2026, 9:02 a.m.
Summary
The Rust Security Response Team issued a security advisory regarding a vulnerability (CVE-2026-5222) in Cargo that improperly normalizes URLs for third-party registries using the sparse index protocol, potentially allowing credential theft under specific circumstances. The issue, due to be fixed in Rust 1.96, affects all versions shipped between Rust 1.68 and 1.96, reminding users to upgrade their Cargo version to mitigate risks.