CVE-2026-5223
Estado: AnalizadaMedia (6.5)—
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-61
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-5223",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-5223",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-26T14:36:37.949868Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 6.5,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "PASSIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"affectedData": [
{
"repo": "https://github.com/rust-lang/cargo",
"vendor": "Rust Project",
"product": "Cargo",
"versions": [
{
"status": "affected",
"version": "1.0.0",
"lessThan": "1.96.0",
"versionType": "semver"
}
],
"packageName": "cargo",
"collectionURL": "https://crates.io",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-25T10:16:15.480",
"references": [
{
"url": "https://blog.rust-lang.org/2026/05/25/cve-2026-5223/",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
},
{
"url": "https://github.com/rust-lang/cargo/pull/17031",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
},
{
"url": "https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "986d4109-89ea-491f-99fd-a8e4803919bd"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "986d4109-89ea-491f-99fd-a8e4803919bd",
"description": [
{
"lang": "en",
"value": "CWE-61"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink."
},
{
"lang": "es",
"value": "Cargo gestionó incorrectamente los enlaces simbólicos dentro de los tarballs de crates descargados de registros de terceros, permitiendo que un crate malicioso sobrescribiera el código fuente de otro crate del mismo registro. La gravedad de la vulnerabilidad es media para los usuarios de registros de terceros. Los usuarios de crates.io no se ven afectados, ya que crates.io prohíbe subir crates que contengan enlaces simbólicos."
}
],
"lastModified": "2026-07-23T17:10:00.123",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:*",
"vulnerable": true,
"matchCriteriaId": "67F6F381-6055-48F2-A156-047F903ABE84",
"versionEndExcluding": "1.96.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "986d4109-89ea-491f-99fd-a8e4803919bd"
}