cargo vulnerabilities
CVEs whose affected-version data names the cargo package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-5222LowCargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
▾ Sunlitcargo · cargoEPSS 0.48%via GHSA
CVE-2026-5223MediumCargo crates in third party registries can override the cached source of other crates
Cargo crates in third party registries can override the cached source of other crates
▾ Sunlitcargo · cargoEPSS 0.29%via GHSA
CVE-2026-39840Medium· 6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extensio…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows XSS Targeting Non-Script Elements.This issue affects Mediawiki - Cargo Extensio…
▾ Sunlitmediawiki · cargoEPSS 0.16%via NVD