MEDIUM4.2crates.io
GHSA-2hvr-h6gw-qrxp· CVE-2022-36114Cargo extracting malicious crates can fill the file system
Modified: 11/8/2023
package
pkg:crates.io/cargo
Cargo extracting malicious crates can fill the file system
Modified: 11/8/2023
Cargo prior to Rust 1.26.0 may download the wrong dependency
Modified: 9/10/2026
Cargo not respecting umask when extracting crate archives
Modified: 11/8/2023
Cargo crates in third party registries can override the cached source of other crates
Modified: 6/26/2026
Cargo can be coerced to share credentials between registries
Modified: 6/26/2026
Cargo did not verify SSH host keys
Modified: 11/8/2023
Cargo extracting malicious crates can corrupt arbitrary files
Modified: 11/8/2023
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
Modified: 9/10/2026