{"api_version":"v1","generated_at":"2026-10-07T00:40:00+00:00","product":{"cve_count":1,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rust-cargo-3e295c80c95d","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cargo","name":"cargo","next_cursor":null,"observations":[{"affected":"1.68.0 < 1.96.0","affected_versions_present":true,"cve_id":"CVE-2026-5222","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5222","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-26T14:43:10.019Z","patch_url":"https://github.com/rust-lang/cargo/pull/17031","primary_source":"","published":"2026-05-25T08:54:56.348Z"},{"affected":"1.0.0 < 1.26.0","affected_versions_present":true,"cve_id":"CVE-2019-16760","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16760","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T01:24:48.330Z","patch_url":"https://gist.github.com/pietroalbini/0d293b24a44babbeb6187e06eebd4992","primary_source":"","published":"2019-09-30T21:39:38.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"rust"}}
