# Rust Security Advisory for Cargo (CVE-2026-5223) - Product: Rust (https://whatsnew.fyi/product/rust) - Vendor: Rust Foundation - Date: 2026-05-25 - Original notes: https://blog.rust-lang.org/2026/05/25/cve-2026-5223/ - Permalink: https://whatsnew.fyi/product/rust/releases/2026-05-25-security-advisory-for-cargo-cve-2026-5223 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- The Rust Security Response Team was notified that Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source… - **security** — Fixed Cargo incorrectly handling symlinks inside of crate tarballs downloaded from third-party registries that could allow a malicious crate to override source files