GHSA-w476-p2h3-79g9

    Dashboard / Vulnerabilities / GHSA-w476-p2h3-79g9

    GHSA-w476-p2h3-79g9

    Published: 21 Oct 2025Last Modified: 4 Feb 2026

    Summary: uv has differential in tar extraction with PAX headers

    Details: ### Impact In versions 0.9.4 and earlier of uv, tar archives containing PAX headers with file size overrides were not handled properly. As a result, an attacker could contrive a source distribution (as a tar archive) that would extract differently when installed via uv versus other Python package installers. The underlying parsing differential here originates with astral-tokio-tar, which disclosed this vulnerability as CVE-2025-62518. In practice, the impact of this vulnerability is **low**: only source distributions can be formatted as tar archives, and source distributions execute arbitrary code at build/installation time by definition. Consequently, a parser differential in tar extraction is strictly less powerful than the capabilities already exposed to an attacker who has the ability to control source distributions. However, this particular source of malleability in source distributions is unintentional and not operating by design, and therefore we consider it a vulnerability despite its overlap in capabilities with intended behavior. ### Patches Versions 0.9.5 and newer of uv address the vulnerability above. Users should upgrade to 0.9.5 or newer. ### Workarounds Users are advised to upgrade to version 0.9.5 or newer to address this advisory. Users should experience no breaking changes as a result of the patch above. ### References * See CVE-2025-62518 for the corresponding advisory against astral-tokio-tar

    Affected packages

    Package

    Name: uv

    Purl: pkg:pypi/uv

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.9.5

    Affected versions

    0.0.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w476-p2h3-79g9 | CVE-DB