Cargo
Rust · 2 CVEs
CVE-2026-5223
MEDIUM
Crates in third party registries can override the cached source of other crates
May 25, 2026
CVE-2026-5222
LOW
Cargo can be coerced to share credentials between registries
May 25, 2026
CVE-2019-16760
HIGH
Cargo prior to Rust 1.26.0 may download the wrong dependency
Sep 30, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-5223 | Crates in third party registries can override the cached source of other crates | MEDIUM | 0.41% | May 25, 2026 |
| CVE-2026-5222 | Cargo can be coerced to share credentials between registries | LOW | 0.50% | May 25, 2026 |
| CVE-2019-16760 | Cargo prior to Rust 1.26.0 may download the wrong dependency | HIGH | 1.26% | Sep 30, 2019 |
Showing 1 to 2 of 2 CVEs