{"api_version":"v1","generated_at":"2026-10-07T14:55:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-rust-lang-cargo-59bd5f2b539e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cargo","name":"cargo","next_cursor":null,"observations":[{"affected":">= 1.60.0, < 1.72","affected_versions_present":true,"cve_id":"CVE-2023-40030","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40030","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T19:09:34.361Z","patch_url":"https://github.com/rust-lang/cargo/pull/12291","primary_source":"","published":"2023-08-24T22:56:41.085Z"},{"affected":"< 0.72.2","affected_versions_present":true,"cve_id":"CVE-2023-38497","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-38497","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:01:51.522Z","patch_url":"https://github.com/rust-lang/cargo/pull/12443","primary_source":"","published":"2023-08-04T15:51:44.878Z"},{"affected":"<= 0.67.0","affected_versions_present":true,"cve_id":"CVE-2022-46176","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-46176","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-10T21:30:29.733Z","patch_url":"https://github.com/rust-lang/wg-security-response/tree/main/patches/CVE-2022-46176","primary_source":"","published":"2023-01-11T20:07:12.847Z"},{"affected":"< 0.65.0; = 0.66.0","affected_versions_present":true,"cve_id":"CVE-2022-36114","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36114","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:10:50.866Z","patch_url":"https://github.com/rust-lang/cargo/commit/d1f9553c825f6d7481453be8d58d0e7f117988a7","primary_source":"","published":"2022-09-14T00:00:00.000Z"},{"affected":"< 0.65.0; = 0.66.0","affected_versions_present":true,"cve_id":"CVE-2022-36113","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36113","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:10:57.339Z","patch_url":"https://github.com/rust-lang/cargo/commit/97b80919e404b0768ea31ae329c3b4da54bed05a","primary_source":"","published":"2022-09-14T00:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"rust-lang"}}
