ended3월 22일· 1 sources

Security advisory for Cargo

Cargo 보안 권고

Why it matters

A vulnerability (CVE-2026-33056) was found in the tar crate used by Cargo, allowing malicious crates to change permissions on arbitrary directories during extraction. Crates.io was patched on March 13th and audited with no exploits found; Rust 1.94.1 with a fix is scheduled for March 26th, 2026.

1
Sources
+0
24h
Growth
183d
Active
CargoRustCVE-2026-33056crates.iotar crate

Sources

Related Issues