lowVulnerability

CVE-2026-5222

The Rust Security Response Team was notified that Cargo incorrectly normalized the URLs of third-party registries using the [sparse index protocol][1]. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. This vulnerability is tracked as CVE-2026-5222. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack. ## Overview Originally Cargo only supported storing a registry's index within git repositories. Most git hosting solutions allow accessing a git repository with or without the `.git` suffix, so Cargo mirrored this behavior when normalizing registry URLs. This allowed credentials for `https://example.com/index` to be used for `https://example.com/index.git`. This normalization was unintentionally applied to the new sparse indexes too. Sparse indexes can be hosted on any HTTPS server, which treat URLs ending with `.git` as different URLs than those without the suffix. If the following conditions apply: * `https://example.com/index` is a sparse index. * `https://example.com/index` allows crates to depend on crates from any other registry. * The attacker is able to publish crates on `https://example.com/index`. * The attacker is able to upload arbitrary files to `https://example.com/index.git`. ...the attacker could configure `https://example.com/index.git` to be a Cargo sparse registry requiring authentication for downloads, and with a download URL pointing to a server recording any credentials set to it. When the attacker then publishes a crate `foo` to `https://example.com/index` depending on a crate `bar` from `https://example.com/index.git`, and tricks the victim into downloading `foo`, Cargo will think the two registries share the same credential and send the victim's Cargo token to the malicious registry. ## Mitigations Ru

Properties

ghsa_id
GHSA-p688-r7jv-fm6f
summary
Cargo can be coerced to share credentials between registries
severity
low
epss_score
0.00478
cve_id
CVE-2026-5222
is_ghsa_only
false
ghsa_published
2026-06-26T21:47:54Z
source_url
https://github.com/advisories/GHSA-p688-r7jv-fm6f
epss_percentile
0.38785
ghsa_updated
2026-06-26T21:47:56Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/cargo

AFFECTS (1)

[Software]rust/cargo

HAS_WEAKNESS (1)

[Weakness]Use of Non-Canonical URL Paths for Authorization Decisions

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5222 — Ninja Signal Threat Intelligence | Ninja Signal