rust-lang/cargo · error
error: SSH host key has changed for
Error message
error: SSH host key has changed for `{hostname}`
*********************************
* WARNING: HOST KEY HAS CHANGED *
*********************************
This may be caused by a man-in-the-middle attack, or the server may have changed its host key.
The {key_type_short_name} fingerprint for the key from the remote host is:
SHA256:{remote_fingerprint}
You are strongly encouraged to contact the server administrator for `{hostname}` to verify that this new key is correct.
If you can verify that the server has a new key, you can resolve this error by {old_key_resolution}
The key provided by the remote host is:
{hostname} {key_type_name} {remote_host_key}
See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information.
What it means
Error "error: SSH host key has changed for `{hostname}` ********************************* * WARNING: HOST KEY HAS CHANGED * ********************************* This may be caused by a man-in-the-middle attack, or the server may have changed its host key. The {key_type_short_name} fingerprint for the key from the remote host is: SHA256:{remote_fingerprint} You are strongly encouraged to contact the server administrator for `{hostname}` to verify that this new key is correct. If you can verify that the server has a new key, you can resolve this error by {old_key_resolution} The key provided by the remote host is: {hostname} {key_type_name} {remote_host_key} See https://doc.rust-lang.org/stable/cargo/appendix/git-authentication.html#ssh-known-hosts for more information. " thrown in rust-lang/cargo.
When it happens
Trigger: Thrown at src/sources/git/known_hosts.rs:264 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
AI-assisted analysis of rust-lang/cargo@eb98b54bc9 (2026-08-11).
Data as JSON: /api/errors/52a6e6c3e9802163.
Report an issue: GitHub.
Appendix: source
Thrown at src/sources/git/known_hosts.rs:264
located at {old_key_location} line {lineno}, \
and adding the new key to {known_hosts_location}",
)
}
KnownHostLocation::Config { definition } => {
format!(
"removing the old {key_type_name} key for `{hostname}` \
loaded from Cargo's config at {definition}, \
and adding the new key to {known_hosts_location}"
)
}
KnownHostLocation::Bundled => {
format!(
"adding the new key to {known_hosts_location}\n\
The current host key is bundled as part of Cargo."
)
}
};
anyhow::bail!(
"error: SSH host key has changed for `{hostname}`\n\
*********************************\n\
* WARNING: HOST KEY HAS CHANGED *\n\
*********************************\n\
This may be caused by a man-in-the-middle attack, or the \
server may have changed its host key.\n\
\n\
The {key_type_short_name} fingerprint for the key from the remote host is:\n\
SHA256:{remote_fingerprint}\n\
\n\
You are strongly encouraged to contact the server \
administrator for `{hostname}` to verify that this new key is \
correct.\n\
\n\
If you can verify that the server has a new key, you can \
resolve this error by {old_key_resolution}\n\
\n\
The key provided by the remote host is:\n\View on GitHub (pinned to eb98b54bc9)