HIGH8.1crates.io
GHSA-j5gw-2vrg-8fgx· CVE-2025-62518, RUSTSEC-2025-0110astral-tokio-tar Vulnerable to PAX Header Desynchronization
Modified: 9/10/2026
package
pkg:crates.io/tokio-tar
astral-tokio-tar Vulnerable to PAX Header Desynchronization
Modified: 9/10/2026
`tokio-tar` parses PAX extended headers incorrectly, allows file smuggling
Modified: 2/4/2026