CVE-2026-5222
Estado: AnalizadaBaja (2.3)—
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 2.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-647
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-5222",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-5222",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-26T14:36:59.303136Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 2.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"affectedData": [
{
"repo": "https://github.com/rust-lang/cargo",
"vendor": "Rust",
"modules": [
"sparse index"
],
"product": "Cargo",
"versions": [
{
"status": "affected",
"version": "1.68.0",
"lessThan": "1.96.0",
"versionType": "semver"
}
],
"packageName": "cargo",
"collectionURL": "https://crates.io",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-25T10:16:15.273",
"references": [
{
"url": "https://blog.rust-lang.org/2026/05/25/cve-2026-5222/",
"tags": [
"Vendor Advisory"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
},
{
"url": "https://github.com/rust-lang/cargo/pull/17031",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
},
{
"url": "https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"description": [
{
"lang": "en",
"value": "CWE-647"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack."
},
{
"lang": "es",
"value": "Cargo entre 1.68 y 1.96 normalizó incorrectamente las URL de registros de terceros utilizando el protocolo de índice disperso. Si un proveedor de alojamiento permitía que se alojaran múltiples registros con nombres arbitrarios dentro del mismo dominio, un atacante capaz de publicar crates en un registro podría obtener las credenciales de otros usuarios del mismo registro. La gravedad de la vulnerabilidad es baja, debido a los requisitos extremadamente específicos necesarios para lograr el ataque."
}
],
"lastModified": "2026-07-23T17:10:00.123",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "143A0C07-6AA8-4711-A789-152DA178214C",
"versionEndExcluding": "1.96.0",
"versionStartIncluding": "1.68.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "986d4109-89ea-491f-99fd-a8e4803919bd"
}