CVE-2025-62518Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 6 days

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-24: 1Mentions · 2026-03-18: 1Mentions · 2026-05-06: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-07-26: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-18: 1Technical Details · 2026-05-06: 102-1702-1802-2403-1805-0607-26
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-171
General1
2026-02-181
General1
2026-02-241
Disclosure1
2026-03-181
Disclosure1
2026-05-061
Disclosure1
2026-07-261
Patch1
Full discourse6 posts
  • reverseame@reverseame
    Disclosure

    TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware #TARmageddon #CVE202562518 #OpenSourceSecurity #Abandonware #RCEVulnerability https://edera.dev/stories/tarmageddon

    Post summary

    A new RCE vulnerability (CVE-2025-62518) in an abandoned open‑source project has been disclosed, underscoring the risks associated with unmaintained software.

    08016111.7K
    21.6K followersView on X
  • Mistralol@mistralol
    General

    @nksages @Franc0Fernand0 No, Also rust doesn't do memory safty much better. Cause the hard parts are validation, race conditions, concurrenty, state control and rust has proven it can't deal with this either. Example: https://nvd.nist.gov/vuln/detail/CVE-2025-62518

    Post summary

    The tweet merely comments that Rust does not fully address memory safety issues and links to the NVD entry for CVE-2025-62518, without providing additional details or claims.

    0002081
    22 followersView on X
  • Sergii Demianchuk@SergiiDemian
    Patch

    tokio-tar: 5M+ downloads. Zero maintainers. CVE-2025-62518 will never be patched. Every traditional health metric said the library was alive. It wasn't. My new peer-reviewed paper on measuring end-of-life risk before it becomes an incident: https://www.linkedin.com/posts/sdemian_cybersecurity-supplychainsecurity-opensource-share-7487206903165513730-U8Aw/ https://t.co/1eerdg44rN

    Post summary

    The post highlights that the unmaintained tokio-tar library, which has CVE‑2025‑62518, will never receive a patch, underscoring the end‑of‑life risk of using this component.

    0000021
    7 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 astral-tokio-tar, PAX Header Desynchronization, #CVE-2025-62518 (High) https://dailycve.com/astral-tokio-tar-pax-header-desynchronization-cve-2025-62518-high-2/

    Post summary

    The text announces a high‑severity CVE‑2025‑62518 involving a PAX header desynchronization flaw in astral-tokio-tar, with a link for further details.

    00000656
    196 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 astral-tokio-tar, PAX Header Desynchronization, #CVE-2025-62518 (HIGH) https://dailycve.com/astral-tokio-tar-pax-header-desynchronization-cve-2025-62518-high/

    Post summary

    The tweet announces the disclosure of CVE‑2025‑62518, a high‑severity PAX header desynchronization flaw in astral‑tokio‑tar, with a link to a detailed article.

    0000042
    169 followersView on X
  • Mistralol@mistralol
    General

    @JustDeezGuy Rust doesn't solve the problems you think it solves.... https://nvd.nist.gov/vuln/detail/CVE-2025-62518

    Post summary

    The tweet only links to the NVD entry for CVE-2025-62518 without providing additional context or details.

    00000206
    22 followersView on X

Explore more