Async-tar/tokio-tar boundary parsing flaw (CVE-2025-62518)
Vulnerability
Summary
Hide ▲
Show ▼
A high-severity TAR parsing flaw in async-tar and tokio-tar now puts archive extraction workflows at risk of remote code execution and file overwriting. The issue, tracked as CVE-2025-62518 and nicknamed TARmageddon, exploits inconsistent PAX/ustar boundary handling to smuggle hidden archive entries. Users of tokio-tar are advised to migrate to astral-tokio-tar 0.5.6 to remediate the bug.
Related Happenings
Tokio-tar remediation guidance (CVE-2025-62518)
Advisory/Mitigation
First: 22.10.2025 20:21
Last: 22.10.2025 20:21
Sources 1
How related:
Edera advises developers to either upgrade to a patched version or immediately remove the vulnerable tokio-tar dependency.
About this happening:
**Edera** told developers using **tokio-tar** to **upgrade to a patched version** or **immediately remove** the dependency because **CVE-2025-62518** leaves projects exposed to ar...
Tokio-tar remediation guidance (CVE-2025-62518)
Advisory/MitigationHow related: Edera advises developers to either upgrade to a patched version or immediately remove the vulnerable tokio-tar dependency.
About this happening: **Edera** told developers using **tokio-tar** to **upgrade to a patched version** or **immediately remove** the dependency because **CVE-2025-62518** leaves projects exposed to ar...
Timeline
-
22.10.2025 10:05 3 articles · 7mo ago
Researchers disclose CVE-2025-62518 in async-tar and tokio-tar
Initial DisclosureA high-severity parsing flaw in the async-tar Rust library and forks including tokio-tar, tracked as CVE-2025-62518 and nicknamed TARmageddon, allows crafted TAR archives to exploit inconsistent PAX/ustar header handling, smuggle nested archive entries, overwrite files within extraction directories, and potentially reach remote code execution; users relying on tokio-tar are advised to migrate to astral-tokio-tar 0.5.6.
Show sources
- TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution — thehackernews.com — 22.10.2025 10:05
- TARmageddon Flaw in Async-Tar Rust Library Could Enable Remote Code Execution — thehackernews.com — 22.10.2025 10:05
- TARmageddon flaw in abandoned Rust library enables RCE attacks — www.bleepingcomputer.com — 22.10.2025 20:21