CVE-2026-5223
EUVD-2026-3165825.05.2026, 10:16
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rust-lang | cargo | 𝑥 < 1.96.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rustc-1.85 |
| ||||||||||||||
| rustc-1.88 |
| ||||||||||||||
| rustc-1.91 |
| ||||||||||||||
| cargo |
| ||||||||||||||
| rustc |
| ||||||||||||||
| rustc-1.62 |
| ||||||||||||||
| rustc-1.74 |
| ||||||||||||||
| rustc-1.76 |
| ||||||||||||||
| rustc-1.77 |
| ||||||||||||||
| rustc-1.78 |
| ||||||||||||||
| rustc-1.79 |
| ||||||||||||||
| rustc-1.80 |
| ||||||||||||||
| rustc-1.81 |
| ||||||||||||||
| rustc-1.82 |
| ||||||||||||||
| rustc-1.83 |
| ||||||||||||||
| rustc-1.84 |
| ||||||||||||||
| rustc-1.89 |
| ||||||||||||||
| rustc-1.92 |
| ||||||||||||||
| rustc-1.93 |
|