<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:40:51.368856+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08151</id>
    <title>bdu:2026-08151</title>
    <updated>2026-10-03T11:40:51.473153+00:00</updated>
    <content>bdu:2026-08151</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-5222</id>
    <title>BELL-CVE-2026-5222</title>
    <updated>2026-10-03T11:40:51.473193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: rust, Alpaquita:25: rust, Alpaquita:stream: rust</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-5222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321379</id>
    <title>EUVD-2026-321379</title>
    <updated>2026-10-03T11:40:51.473224+00:00</updated>
    <content>EUVD-2026-321379</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5222</id>
    <title>fkie_cve-2026-5222</title>
    <updated>2026-10-03T11:40:51.473238+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-5222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p688-r7jv-fm6f</id>
    <title>GHSA-p688-r7jv-fm6f — Cargo can be coerced to share credentials between registries</title>
    <updated>2026-10-03T11:40:51.473264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: cargo</p>
<p>The Rust Security Response Team was notified that Cargo incorrectly normalized the URLs of third-party registries using the [sparse index protocol][1]. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry.</p>
<p>This vulnerability is tracked as CVE-2026-5222. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.</p>
<p>## Overview</p>
<p>Originally Cargo only supported storing a registry's index within git repositories. Most git hosting solutions allow accessing a git repository with or without the `.git` suffix, so Cargo mirrored this behavior when normalizing registry URLs. This allowed credentials for `https://example.com/index` to be used for `https://example.com/index.git`.</p>
<p>This normalization was unintentionally applied to the new sparse indexes too. Sparse indexes can be hosted on any HTTPS server, which treat URLs ending with `.git` as different URLs than those without the suffix.</p>
<p>If the following conditions apply:</p>
<p>* `https://example.com/index` is a sparse index.
* `https://example.com/index` allows crates to depend on crates from any other registry.
* The attacker is able to publish crates on `https://example.com/index`.
* The attacker is able to upload arbitrary files to `https://example.com/index.git`.</p>
<p>...the attacker could configure `https://example…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p688-r7jv-fm6f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-5222</id>
    <title>msrc_CVE-2026-5222 — Cargo can be coerced to share credentials between registries</title>
    <updated>2026-10-03T11:40:51.473309+00:00</updated>
    <content>msrc_CVE-2026-5222</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-5222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5222</id>
    <title>UBUNTU-CVE-2026-5222</title>
    <updated>2026-10-03T11:40:51.473327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rustc, Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:16.04:LTS: rustc, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: rustc, Ubuntu:Pro:20.04:LTS: cargo, Ubuntu:Pro:20.04:LTS: rustc, Ubuntu:Pro:20.04:LTS: rustc-1.76, Ubuntu:Pro:20.04:LTS: rustc-1.77, Ubuntu:Pro:20.04:LTS: rustc-1.78 and 37 more</p>
<p>Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary names within the same domain, an attacker able to publish crates in a registry could obtain the credentials of others users of the same registry. The severity of the vulnerability is **low**, due to the extremely niche requirements needed to achieve the attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-5222"/>
  </entry>
</feed>
