<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:18:31.826991+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00687</id>
    <title>bdu:2023-00687</title>
    <updated>2026-10-03T11:18:32.030968+00:00</updated>
    <content>bdu:2023-00687</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00687"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-46176</id>
    <title>Withdrawn: BELL-CVE-2022-46176 — CVE-2022-46176 does not affect BellSoft software</title>
    <updated>2026-10-03T11:18:32.031024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-46176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ka82053</id>
    <title>CLEANSTART-2026-KA82053 — Security fix for CVE-2022-46176 applied in: rust 1.66.1-r0</title>
    <updated>2026-10-03T11:18:32.031060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: rust</p>
<p>Security vulnerability affects the rust package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ka82053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221686</id>
    <title>EUVD-2026-221686</title>
    <updated>2026-10-03T11:18:32.031107+00:00</updated>
    <content>EUVD-2026-221686</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46176</id>
    <title>fkie_cve-2022-46176</title>
    <updated>2026-10-03T11:18:32.031128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don't explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git's [`url.&lt;base&gt;.insteadOf`][1] setting), as that'd cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server's public key is not already trusted. We recommend everyone to upgrade as soon as possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-46176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r5w3-xm58-jv6j</id>
    <title>GHSA-r5w3-xm58-jv6j — Cargo did not verify SSH host keys</title>
    <updated>2026-10-03T11:18:32.031171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: cargo</p>
<p>The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks.</p>
<p>This vulnerability has been assigned CVE-2022-46176.</p>
<p>## Overview</p>
<p>When an SSH client establishes communication with a server, to prevent MITM attacks the client should check whether it already communicated with that server in the past and what the server's public key was back then. If the key changed since the last connection, the connection must be aborted as a MITM attack is likely taking place.</p>
<p>It was discovered that Cargo never implemented such checks, and performed no validation on the server's public key, leaving Cargo users vulnerable to MITM attacks.</p>
<p>## Affected Versions</p>
<p>All Rust versions containing Cargo before 1.66.1 are vulnerable (prior to 0.67.1 for the crates.io package).</p>
<p>Note that even if you don't explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git's [`url.&lt;base&gt;.insteadOf`][1] setting), as that'd cause you to clone the crates.io index through SSH.</p>
<p>## Mitigations</p>
<p>We will be releasing Rust 1.66.1 today, 2023-01-10, changing Cargo to check the SSH host key and abort the connection if the server's public key is not already trusted. We recommend everyone to upgrade as soon as possible.</p>
<p>Pat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r5w3-xm58-jv6j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-46176</id>
    <title>gsd-2022-46176</title>
    <updated>2026-10-03T11:18:32.031264+00:00</updated>
    <content>gsd-2022-46176</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-46176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-46176</id>
    <title>msrc_CVE-2022-46176 — Cargo did not verify SSH host keys</title>
    <updated>2026-10-03T11:18:32.031286+00:00</updated>
    <content>msrc_CVE-2022-46176</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-46176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1236</id>
    <title>OESA-2025-1236 — rust security update</title>
    <updated>2026-10-03T11:18:32.031311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: rust</p>
<p>Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.

Security Fix(es):</p>
<p>Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;apos;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;apos;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;apos;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;apos;s public key is not already trusted. We recommend everyone to upgrade as soon as possible. (CVE-2022-46176)</p>
<p>Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the sour…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12607-1</id>
    <title>openSUSE-SU-2024:12607-1 — cargo1.65-1.65.0-4.1 on GA media</title>
    <updated>2026-10-03T11:18:32.031373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cargo1.65-1.65.0-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12607-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46176</id>
    <title>UBUNTU-CVE-2022-46176</title>
    <updated>2026-10-03T11:18:32.031400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:20.04:LTS: cargo, Ubuntu:22.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: rust-cargo</p>
<p>Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don't explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git's [`url.&lt;base&gt;.insteadOf`][1] setting), as that'd cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server's public key is not already trusted. We recommend everyone to upgrade as soon as possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46176"/>
  </entry>
</feed>
