This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Rust · Archive · Week 15 · Apr 7 – 13, 2025

Crates.io security incident: improperly stored session cookies

Breakingecosystem

What changed
The Rust team reported that session cookies were improperly stored on crates.io.
Production impact
The source does not say.
Try it
Inspect the session cookie handling in your crates.io login flow or review the security advisory for details.
Source
blog.rust-lang.org/2025/04/11/crates-io-security-session-cookies/

Understand it, then run it

Crates.io, the site that hosts Rust libraries, had a security issue. When an error happened on the site, a cookie that tells the server who you are was sent to an error‑tracking service called Sentry. That cookie can let someone pretend to be you, so it should not have been sent. The team fixed it by removing the cookie from all future error reports and by logging everyone out so the old cookies are no longer useful.

Run it now

Todayrust
// This program demonstrates how to redact a cookie value before sending it to an error
// monitoring service. The crates.io incident showed that sending the raw cookie was a
// security risk. In real life, you would replace the `send_to_sentry` call with the
// actual Sentry SDK integration.

fn main() {
    // Simulated cookie value that would normally be sent to Sentry.
    let cookie = "signed_cookie_value";

    // Redact the cookie before logging the error.
    let redacted_cookie = redact_cookie(cookie);

    // Simulate sending the error event to Sentry.
    send_to_sentry(redacted_cookie);
}

fn redact_cookie(cookie: &str) -> String {
    // Replace the cookie value with a placeholder to avoid leaking user data.
    format!("REDACTED_COOKIE: {}", cookie)
}

fn send_to_sentry(_payload: String) {
    // In a real application, this would send the payload to Sentry.
    // Here we just print it to show the redaction.
    println!("Error event sent to Sentry with payload: {}", _payload);
}

What it printed when we ran it on Rust 1.98.1 (edition 2024)

Error event sent to Sentry with payload: REDACTED_COOKIE: signed_cookie_value

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed