RUSTSEC-2025-0111

    Dashboard / Vulnerabilities / RUSTSEC-2025-0111

    RUSTSEC-2025-0111

    Published: 21 Oct 2025Last Modified: 4 Feb 2026

    Summary: `tokio-tar` parses PAX extended headers incorrectly, allows file smuggling

    Details: The archive reader incorrectly handles PAX extended headers, when the ustar header incorrectly specifies zero size (`size=000000000000`), while a PAX header specifies a non-zero size, `tokio-tar::Archive` is going to read the file content as tar entry header. This can be used by a tar file to present different content to `tokio-tar` compared to other tar reader implementations. This bug is also known as `CVE-2025-62518` and `GHSA-j5gw-2vrg-8fgx`, as those crates share a common ancestor codebase. The `tokio-tar` crate is archived and no longer maintained, we recommend you switch to an alternative crate such as: - [`astral-tokio-tar`](https://crates.io/crates/astral-tokio-tar)

    Affected packages

    Package

    Name: tokio-tar

    Purl: pkg:cargo/tokio-tar

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2025-0111 | CVE-DB