Radar · Rust · Archive · Week 15 · Apr 7 – 13, 2025
Crates.io security incident: improperly stored session cookies
Breakingecosystem
- What changed
- The Rust team reported that session cookies were improperly stored on crates.io.
- Production impact
- The source does not say.
- Try it
- Inspect the session cookie handling in your crates.io login flow or review the security advisory for details.
- Source
- blog.rust-lang.org/2025/04/11/crates-io-security-session-cookies/
Understand it, then run it
Crates.io, the site that hosts Rust libraries, had a security issue. When an error happened on the site, a cookie that tells the server who you are was sent to an error‑tracking service called Sentry. That cookie can let someone pretend to be you, so it should not have been sent. The team fixed it by removing the cookie from all future error reports and by logging everyone out so the old cookies are no longer useful.
Run it now
// This program demonstrates how to redact a cookie value before sending it to an error
// monitoring service. The crates.io incident showed that sending the raw cookie was a
// security risk. In real life, you would replace the `send_to_sentry` call with the
// actual Sentry SDK integration.
fn main() {
// Simulated cookie value that would normally be sent to Sentry.
let cookie = "signed_cookie_value";
// Redact the cookie before logging the error.
let redacted_cookie = redact_cookie(cookie);
// Simulate sending the error event to Sentry.
send_to_sentry(redacted_cookie);
}
fn redact_cookie(cookie: &str) -> String {
// Replace the cookie value with a placeholder to avoid leaking user data.
format!("REDACTED_COOKIE: {}", cookie)
}
fn send_to_sentry(_payload: String) {
// In a real application, this would send the payload to Sentry.
// Here we just print it to show the redaction.
println!("Error event sent to Sentry with payload: {}", _payload);
}
What it printed when we ran it on Rust 1.98.1 (edition 2024)
Error event sent to Sentry with payload: REDACTED_COOKIE: signed_cookie_value
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed