Cargo

Vendor:

First CVE: Sep 14, 2022 · Active for 3 years

6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cargo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2022
3 years ago
Most Recent CVE
May 25, 2026
60 days ago

CVE Severity & Scoring

Cargo6 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low2 (33.3%)
High0 (0.0%)
None4 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hoste
May 25, 20266.532NONO
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the
May 25, 20265.329NONO
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to t
Sep 14, 20228.127NONO
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when e
Aug 4, 20237.323NONO
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could up
Sep 14, 20226.523NONO
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An a
Jan 11, 20235.921NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Cargo

Top CWEs

Versions

No cataloged versions.