Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88278.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-88278
Upstream
  • CVE-2026-5223
Published
2026-05-25T10:16:15Z
Modified
2026-09-20T05:33:47Z
Summary
CVE-2026-5223 affecting package rust for versions less than 1.90.0-9
Details

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.

References

Affected packages

Azure Linux:3 / rust

Package

Name
rust
Purl
pkg:rpm/azure-linux/rust

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.85.0
Fixed
1.90.0-9

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88278.json"