CVE-2022-36114 affects Cargo, the package manager for Rust, allowing an attacker to craft a "zip bomb" package that exhausts disk space when downloaded from an alternate registry. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and high impact on availability, requiring user interaction. While not actively exploited in the wild and lacking public exploit code, the community has shown some awareness. Rust 1.64 will include a fix, but users are advised to trust dependencies due to inherent build-time code execution capabilities in Cargo.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.65.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.