<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:25:43 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-00687</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00687</link>
      <description>bdu:2023-00687</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00687</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-46176 — CVE-2022-46176 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-46176</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-46176</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-KA82053 — Security fix for CVE-2022-46176 applied in: rust 1.66.1-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ka82053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rust&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the rust package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: rust&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the rust package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ka82053</guid>
    </item>
    <item>
      <title>EUVD-2026-221686</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221686</link>
      <description>EUVD-2026-221686</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221686</guid>
    </item>
    <item>
      <title>fkie_cve-2022-46176</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46176</link>
      <description>&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-46176</guid>
    </item>
    <item>
      <title>GHSA-r5w3-xm58-jv6j — Cargo did not verify SSH host keys</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r5w3-xm58-jv6j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cargo&lt;/p&gt;
&lt;p&gt;The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2022-46176.&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;When an SSH client establishes communication with a server, to prevent MITM attacks the client should check whether it already communicated with that server in the past and what the server&amp;#39;s public key was back then. If the key changed since the last connection, the connection must be aborted as a MITM attack is likely taking place.&lt;/p&gt;
&lt;p&gt;It was discovered that Cargo never implemented such checks, and performed no validation on the server&amp;#39;s public key, leaving Cargo users vulnerable to MITM attacks.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;All Rust versions containing Cargo before 1.66.1 are vulnerable (prior to 0.67.1 for the crates.io package).&lt;/p&gt;
&lt;p&gt;Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH.&lt;/p&gt;
&lt;p&gt;## Mitigations&lt;/p&gt;
&lt;p&gt;We will be releasing Rust 1.66.1 today, 2023-01-10, changing Cargo to check the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;
&lt;p&gt;Pat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: cargo&lt;/p&gt;
&lt;p&gt;The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2022-46176.&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;When an SSH client establishes communication with a server, to prevent MITM attacks the client should check whether it already communicated with that server in the past and what the server&amp;#39;s public key was back then. If the key changed since the last connection, the connection must be aborted as a MITM attack is likely taking place.&lt;/p&gt;
&lt;p&gt;It was discovered that Cargo never implemented such checks, and performed no validation on the server&amp;#39;s public key, leaving Cargo users vulnerable to MITM attacks.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;All Rust versions containing Cargo before 1.66.1 are vulnerable (prior to 0.67.1 for the crates.io package).&lt;/p&gt;
&lt;p&gt;Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH.&lt;/p&gt;
&lt;p&gt;## Mitigations&lt;/p&gt;
&lt;p&gt;We will be releasing Rust 1.66.1 today, 2023-01-10, changing Cargo to check the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;
&lt;p&gt;Pat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r5w3-xm58-jv6j</guid>
    </item>
    <item>
      <title>gsd-2022-46176</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-46176</link>
      <description>gsd-2022-46176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-46176</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-46176 — Cargo did not verify SSH host keys</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-46176</link>
      <description>msrc_CVE-2022-46176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-46176</guid>
    </item>
    <item>
      <title>OESA-2025-1236 — rust security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1236</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rust&lt;/p&gt;
&lt;p&gt;Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;amp;apos;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;amp;apos;s [`url.&amp;amp;lt;base&amp;amp;gt;.insteadOf`][1] setting), as that&amp;amp;apos;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;amp;apos;s public key is not already trusted. We recommend everyone to upgrade as soon as possible. (CVE-2022-46176)&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the sour…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: rust&lt;/p&gt;
&lt;p&gt;Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;amp;apos;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;amp;apos;s [`url.&amp;amp;lt;base&amp;amp;gt;.insteadOf`][1] setting), as that&amp;amp;apos;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;amp;apos;s public key is not already trusted. We recommend everyone to upgrade as soon as possible. (CVE-2022-46176)&lt;/p&gt;
&lt;p&gt;Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the sour…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1236</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12607-1 — cargo1.65-1.65.0-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12607-1</link>
      <description>&lt;p&gt;cargo1.65-1.65.0-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cargo1.65-1.65.0-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12607-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-46176</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:20.04:LTS: cargo, Ubuntu:22.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: rust-cargo&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cargo, Ubuntu:Pro:18.04:LTS: cargo, Ubuntu:20.04:LTS: cargo, Ubuntu:22.04:LTS: cargo, Ubuntu:Pro:22.04:LTS: rust-cargo&lt;/p&gt;
&lt;p&gt;Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don&amp;#39;t explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH (through git&amp;#39;s [`url.&amp;lt;base&amp;gt;.insteadOf`][1] setting), as that&amp;#39;d cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server&amp;#39;s public key is not already trusted. We recommend everyone to upgrade as soon as possible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46176</guid>
    </item>
  </channel>
</rss>
