PT-2026-43024 · Rust · Cargo
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cargo versions 1.68 through 1.95
Description
Cargo incorrectly normalized URLs of third-party registries using the sparse index protocol. In scenarios where a hosting provider allows multiple registries to be hosted with arbitrary names within the same domain, an attacker capable of publishing crates in a registry could obtain the credentials of other users of that same registry.
Recommendations
Update to version 1.96.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cargo