VendorsRust-langcargoall versions
Vulnerabilities

Rust-lang Cargo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-36113
Extracting malicious crates can corrupt arbitrary files
Published 2022-09-14 · Modified
8.1EPSS 0.012
CVE-2023-38497
Cargo not respecting umask when extracting crate archives
Published 2023-08-04 · Modified
7.9EPSS 0.007
CVE-2022-36114
Extracting malicious crates can fill the file system
Published 2022-09-14 · Modified
6.5EPSS 0.009
CVE-2026-5222
Cargo can be coerced to share credentials between registries
Published 2026-05-25 · Analyzed
6.5EPSS 0.005
CVE-2026-5223
Crates in third party registries can override the cached source of other crates
Published 2026-05-25 · Analyzed
6.5EPSS 0.004
CVE-2022-46176
Cargo did not verify SSH host keys
Published 2023-01-11 · Modified
5.9EPSS 0.006