Known vulnerabilities in Cargo
Vendor:
The Rust Programming Language
Software:
Cargo
Software CPE:
cpe:2.3::rust-lang:cargo:*:*:*:*:*:*:*:*
Website:
https://github.com/rust-lang/
Total vulnerabilities:
6
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
0.98.0
0.97.2
0.97.1
0.97.0
0.96.0
0.95.0
0.94.0
0.93.0
0.92.0
home-0.5.12
0.91.0
0.90.0
0.89.0
0.88.0
0.87.0
0.86.0
0.85.0
home-0.5.11
0.84.0
0.83.0
0.82.0
0.81.0
0.80.0
0.79.0
0.78.1
0.78.0
0.77.0
0.76.0
0.75.0
0.74.0
0.73.1
0.72.2
0.72.1
0.72.0
0.71.0
0.70.1
home-0.5.5
home-0.5.4
0.70.0
0.69.1
0.69.0
0.68.0
0.67.1
0.67.0
0.66.0
homu-tmp
0.0.1-pre
0.65.0
0.64.0
0.63.1
0.63.0
0.62.0
0.61.1
0.61.0
0.60.0
0.59.0
0.58.0
0.58
0.57.0
0.56.0
0.55.0
0.54.0
0.53.0
0.52.0
0.51.0
0.50.1
0.50.0
0.49.0
0.47.0
0.46.1
0.46.0
0.45.0
0.44.1
0.44.0
0.43.1
0.43.0
0.42.0
0.41.0
0.40.0
0.39.0
0.38.0
0.37.0
0.36.0
0.35.0
0.34.0
0.33.0
0.32.0
0.31.1
0.31.0
0.30.0
0.29.0
0.28.0
0.27.0
0.26.0
0.25.0
0.24.0
0.23.0
0.22.0
0.21.1
0.21.0
0.20.0
0.19.0
0.18.0
0.17.0
0.16.0
0.15.0
0.14.0
0.13.0
0.12.0
0.11.0
0.10.0
0.9.0
0.8.0
0.7.0
0.6.1
0.6.0
0.5.0
0.4.0
0.3.0
0.2.0
0.1.0
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132308 - Use of Non-Canonical URL Paths for Authorization Decisions CVE-2026-5222 |
CWE-647 | Low | 0.97.0 | 26.05.2026 |
SB2026052635 SB2026060249 SB2026060250 and 1 more |
||
| #VU132304 - UNIX Symbolic Link (Symlink) Following CVE-2026-5223 |
CWE-61 | Medium | 0.97.0 | 26.05.2026 |
SB2026052635 SB2026060249 SB2026060250 and 1 more |
||
| #VU78930 - Incorrect Default Permissions CVE-2023-38497 |
CWE-276 | Low | - | 03.08.2023 |
SB2023080354 SB2023080355 SB2023080365 and 16 more |
||
| #VU71491 - Improper Verification of Cryptographic Signature CVE-2022-46176 |
CWE-347 | Medium | 0.67.1 | 24.01.2023 |
SB2023012481 SB2023012485 SB2023012486 and 6 more |
||
| #VU67718 - Resource exhaustion CVE-2022-36114 |
CWE-400 | Medium | 0.65.0 | 28.09.2022 |
SB2022092832 SB2022092833 SB2023011810 and 3 more |
||
| #VU67717 - UNIX Symbolic Link (Symlink) Following CVE-2022-36113 |
CWE-61 | Low | 0.65.0 | 28.09.2022 |
SB2022092832 SB2022092833 SB2023011810 and 3 more |