RUSTSEC-2025-0111
Dashboard / Vulnerabilities / RUSTSEC-2025-0111
RUSTSEC-2025-0111
Summary: `tokio-tar` parses PAX extended headers incorrectly, allows file smuggling
Details: The archive reader incorrectly handles PAX extended headers, when the ustar header incorrectly specifies zero size (`size=000000000000`), while a PAX header specifies a non-zero size, `tokio-tar::Archive` is going to read the file content as tar entry header. This can be used by a tar file to present different content to `tokio-tar` compared to other tar reader implementations. This bug is also known as `CVE-2025-62518` and `GHSA-j5gw-2vrg-8fgx`, as those crates share a common ancestor codebase. The `tokio-tar` crate is archived and no longer maintained, we recommend you switch to an alternative crate such as: - [`astral-tokio-tar`](https://crates.io/crates/astral-tokio-tar)
References: https://crates.io/crates/tokio-tar, https://rustsec.org/advisories/RUSTSEC-2025-0111.html, https://edera.dev/stories/tarmageddon
Affected packages
Package
Name: tokio-tar
Purl: pkg:cargo/tokio-tar
Affected ranges
Type: SEMVER
Events:
