RUSTSEC-2025-0110
Dashboard / Vulnerabilities / RUSTSEC-2025-0110
RUSTSEC-2025-0110
Summary: astral-tokio-tar Vulnerable to PAX Header Desynchronization
Details: Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This vulnerability was disclosed to multiple Rust tar parsers, all derived from the original async-tar fork of tar-rs. For additional information see [Edera's blog post](https://edera.dev/stories/tarmageddon).
References: https://crates.io/crates/astral-tokio-tar, https://rustsec.org/advisories/RUSTSEC-2025-0110.html, https://github.com/advisories/GHSA-j5gw-2vrg-8fgx
Affected packages
Package
Name: astral-tokio-tar
Purl: pkg:cargo/astral-tokio-tar
Affected ranges
Type: SEMVER
Events:
