{"id":"GHSA-p688-r7jv-fm6f","summary":"Cargo can be coerced to share credentials between registries","details":"The Rust Security Response Team was notified that Cargo incorrectly normalized the URLs of third-party registries using the [sparse index protocol][1]. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry.\n\nThis vulnerability is tracked as CVE-2026-5222. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.\n\n## Overview\n\nOriginally Cargo only supported storing a registry's index within git repositories. Most git hosting solutions allow accessing a git repository with or without the `.git` suffix, so Cargo mirrored this behavior when normalizing registry URLs. This allowed credentials for `https://example.com/index` to be used for `https://example.com/index.git`.\n\nThis normalization was unintentionally applied to the new sparse indexes too. Sparse indexes can be hosted on any HTTPS server, which treat URLs ending with `.git` as different URLs than those without the suffix.\n\nIf the following conditions apply:\n\n* `https://example.com/index` is a sparse index.\n* `https://example.com/index` allows crates to depend on crates from any other registry.\n* The attacker is able to publish crates on `https://example.com/index`.\n* The attacker is able to upload arbitrary files to `https://example.com/index.git`.\n\n...the attacker could configure `https://example.com/index.git` to be a Cargo sparse registry requiring authentication for downloads, and with a download URL pointing to a server recording any credentials set to it.\n\nWhen the attacker then publishes a crate `foo` to `https://example.com/index` depending on a crate `bar` from `https://example.com/index.git`, and tricks the victim into downloading `foo`,  Cargo will think the two registries share the same credential and send the victim's Cargo token to the malicious registry.\n\n## Mitigations\n\nRust 1.96, to be released on May 28th, 2026, will update Cargo to only strip the `.git` suffix from registry URLs using the git protocol. No mitigations are available for users of older versions of Cargo.\n\n## Affected versions\n\nAll versions of Cargo shipped between Rust 1.68 (the stabilization of sparse registries) and 1.96 are affected.\n\n## Acknowledgements\n\nCargo would like to thank Christos Papakonstantinou for reporting this issue according to the [Rust security policy][2].\n\nCargo also wants to thank the members of the Rust project who helped address the vulnerability: Arlo Siemens for developing the fix; Weihang Lo, Eric Huss and Emily Albini for reviewing the fix; Emily Albini for writing this advisory; Emily Albini, Josh Stone and Manish Goregaokar for coordinating the disclosure.\n\n[1]: https://doc.rust-lang.org/cargo/reference/registries.html#registry-protocols\n[2]: https://rust-lang.org/policies/security","aliases":["CVE-2026-5222"],"modified":"2026-06-26T22:11:37.863398Z","published":"2026-06-26T21:47:54Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-26T21:47:54Z","nvd_published_at":"2026-05-25T10:16:15Z","cwe_ids":["CWE-647"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/rust-lang/cargo/security/advisories/GHSA-p688-r7jv-fm6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5222"},{"type":"WEB","url":"https://github.com/rust-lang/cargo/pull/17031"},{"type":"WEB","url":"https://blog.rust-lang.org/2026/05/25/cve-2026-5222"},{"type":"PACKAGE","url":"https://github.com/rust-lang/cargo"},{"type":"WEB","url":"https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s"}],"affected":[{"package":{"name":"cargo","ecosystem":"crates.io","purl":"pkg:cargo/cargo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.97.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p688-r7jv-fm6f/GHSA-p688-r7jv-fm6f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}]}