Rust-Lang / Cargo
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-5223 | Crates in third party registries can override the cached source of other crates | MEDIUM | 6.5 | May 25, 2026 |
| CVE-2026-5222 | Cargo can be coerced to share credentials between registries | LOW | 2.3 | May 25, 2026 |
| CVE-2023-40030 | Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports | MEDIUM | 6.1 | Aug 24, 2023 |
| CVE-2023-38497 | Cargo not respecting umask when extracting crate archives | HIGH | 7.9 | Aug 4, 2023 |
| CVE-2022-46176 | Cargo did not verify SSH host keys | MEDIUM | 5.9 | Jan 11, 2023 |
| CVE-2022-36114 | Extracting malicious crates can fill the file system | MEDIUM | 6.5 | Sep 14, 2022 |
| CVE-2022-36113 | Extracting malicious crates can corrupt arbitrary files | HIGH | 8.1 | Sep 14, 2022 |
Showing 1 to 7 of 7 CVEs