tokio-tar
Activity
- Latest release
- 3y ago
- Total releases
- 4
- Cadence
- ~1.2 years
- Last 12 months
- 0
Details
- License
- MIT/Apache-2.0
- First release
- Jan 09, 2020
| Version | Released | |
|---|---|---|
0.3.1
unknown
1 CVE
CVE-2025-62518
GHSA-j5gw-2vrg-8fgx
RUSTSEC-2025-0110
RUSTSEC-2025-0111
Oct 21, 2025
astral-tokio-tar Vulnerable to PAX Header Desynchronization
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryVersions of This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original DetailsVulnerability DescriptionThe vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:
Attack MechanismWhen a TAR file contains:
This creates a header/data desynchronization where the parser's position becomes misaligned with actual file boundaries. Root Cause
ImpactThe impact of this vulnerability depends on where See GHSA-w476-p2h3-79g9 for how this vulnerability affects WorkaroundsUsers are advised to upgrade to version 0.5.6 or newer to address this advisory. There is no workaround other than upgrading. Timeline| Date | Event | | --- | --- | | Aug 21, 2025 | Vulnerability discovered by Edera Security Team | | Aug 21, 2025 | Initial analysis and PoC confirmed | | Aug 22, 2025 | Maintainers notified (privately) | | Aug 25, 2025 | Private patch and test suite shared | | Oct 7, 2025 | Text freeze for GHSA | | Oct 21, 2025 | Coordinated public disclosure and patched releases | Credits
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.3.1
unknown
Dependencies (9)
+ 1 more |
|
0.3.0
unknown
1 CVE
CVE-2025-62518
GHSA-j5gw-2vrg-8fgx
RUSTSEC-2025-0110
RUSTSEC-2025-0111
Oct 21, 2025
astral-tokio-tar Vulnerable to PAX Header Desynchronization
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryVersions of This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original DetailsVulnerability DescriptionThe vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:
Attack MechanismWhen a TAR file contains:
This creates a header/data desynchronization where the parser's position becomes misaligned with actual file boundaries. Root Cause
ImpactThe impact of this vulnerability depends on where See GHSA-w476-p2h3-79g9 for how this vulnerability affects WorkaroundsUsers are advised to upgrade to version 0.5.6 or newer to address this advisory. There is no workaround other than upgrading. Timeline| Date | Event | | --- | --- | | Aug 21, 2025 | Vulnerability discovered by Edera Security Team | | Aug 21, 2025 | Initial analysis and PoC confirmed | | Aug 22, 2025 | Maintainers notified (privately) | | Aug 25, 2025 | Private patch and test suite shared | | Oct 7, 2025 | Text freeze for GHSA | | Oct 21, 2025 | Coordinated public disclosure and patched releases | Credits
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (9)
+ 1 more |
|
0.2.0
unknown
1 CVE
CVE-2025-62518
GHSA-j5gw-2vrg-8fgx
RUSTSEC-2025-0110
RUSTSEC-2025-0111
Oct 21, 2025
astral-tokio-tar Vulnerable to PAX Header Desynchronization
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryVersions of This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original DetailsVulnerability DescriptionThe vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:
Attack MechanismWhen a TAR file contains:
This creates a header/data desynchronization where the parser's position becomes misaligned with actual file boundaries. Root Cause
ImpactThe impact of this vulnerability depends on where See GHSA-w476-p2h3-79g9 for how this vulnerability affects WorkaroundsUsers are advised to upgrade to version 0.5.6 or newer to address this advisory. There is no workaround other than upgrading. Timeline| Date | Event | | --- | --- | | Aug 21, 2025 | Vulnerability discovered by Edera Security Team | | Aug 21, 2025 | Initial analysis and PoC confirmed | | Aug 22, 2025 | Maintainers notified (privately) | | Aug 25, 2025 | Private patch and test suite shared | | Oct 7, 2025 | Text freeze for GHSA | | Oct 21, 2025 | Coordinated public disclosure and patched releases | Credits
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (8)
|
|
0.1.0
unknown
1 CVE
CVE-2025-62518
GHSA-j5gw-2vrg-8fgx
RUSTSEC-2025-0110
RUSTSEC-2025-0111
Oct 21, 2025
astral-tokio-tar Vulnerable to PAX Header Desynchronization
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryVersions of This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original DetailsVulnerability DescriptionThe vulnerability stems from inconsistent handling of PAX extended headers versus ustar headers when determining file data boundaries. Specifically:
Attack MechanismWhen a TAR file contains:
This creates a header/data desynchronization where the parser's position becomes misaligned with actual file boundaries. Root Cause
ImpactThe impact of this vulnerability depends on where See GHSA-w476-p2h3-79g9 for how this vulnerability affects WorkaroundsUsers are advised to upgrade to version 0.5.6 or newer to address this advisory. There is no workaround other than upgrading. Timeline| Date | Event | | --- | --- | | Aug 21, 2025 | Vulnerability discovered by Edera Security Team | | Aug 21, 2025 | Initial analysis and PoC confirmed | | Aug 22, 2025 | Maintainers notified (privately) | | Aug 25, 2025 | Private patch and test suite shared | | Oct 7, 2025 | Text freeze for GHSA | | Oct 21, 2025 | Coordinated public disclosure and patched releases | Credits
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (9)
+ 1 more |