cbcvebase.
CVE-2025-62518
published 2025-10-21

CVE-2025-62518: astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability…

PriorityP344high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
0.68%
48.3th percentile
astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

Affected

12 ranges
VendorProductVersion rangeFixed in
alexcrichtontar-rs< 0.4.450.4.45
alexcrichtontar-rs< 0.4.450.4.45
astral-shtokio-tar0 – 0.3.1
astral-shtokio-tar>= 0.0.0-0
astral-shuv>= 0 < 0.9.50.9.5
debianrust-astral-tokio-tar< rust-astral-tokio-tar 0.5.6-1 (forky)rust-astral-tokio-tar 0.5.6-1 (forky)
debianrust-tar< rust-tar 0.4.45-1 (forky)rust-tar 0.4.45-1 (forky)
debianrustc< rust-tar 0.4.45-1 (forky)rust-tar 0.4.45-1 (forky)
gnutar>= 0 < 0.4.450.4.45
gnutar>= 0.0.0-0 < 0.4.450.4.45
msrcazl3_kata-containers-cc_3.15.0.aks0-5_on_azure_linux_3.0
msrcazl3_kata-containers-cc_3.15.0.aks0-6_on_azure_linux_3.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
ghsa8.1HIGH
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.