VDB
Sign up
—

RUSTSEC-2026-0112

PAX Header Desynchronization in astral-tokio-tar

Details

Versions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle unexpected files onto a victim's filesystem.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/astral-tokio-tar
Introduced in: 0.0.0-0Fixed in: 0.6.1

Upgrade astral-tokio-tar to 0.6.1 or newer (ecosystem crates.io).

References