Radar · Rust · Archive · Week 13 · Mar 23 – 29, 2026
Cargo security advisory (CVE‑2026‑33056)
Breakingtooling
- What changed
- A security advisory for Cargo was published.
- Production impact
- The source does not say.
- Try it
- Check the advisory to see which Cargo versions are affected.
- Source
- blog.rust-lang.org/2026/03/21/cve-2026-33056/
Understand it, then run it
Cargo is the tool that downloads and builds Rust packages. A security problem was found in the tar crate that Cargo uses to unpack packages. The issue could let a bad package change file permissions on your computer when it is built. The Rust team fixed the problem in a new Cargo release and blocked the bad packages from the public registry.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed