RUSTSEC-2025-0111
`tokio-tar` parses PAX extended headers incorrectly, allows file smuggling
Details
The archive reader incorrectly handles PAX extended headers, when the ustar header incorrectly specifies zero size (`size=000000000000`), while a PAX header specifies a non-zero size, `tokio-tar::Archive` is going to read the file content as tar entry header.
This can be used by a tar file to present different content to `tokio-tar` compared to other tar reader implementations.
This bug is also known as `CVE-2025-62518` and `GHSA-j5gw-2vrg-8fgx`, as those crates share a common ancestor codebase.
The `tokio-tar` crate is archived and no longer maintained, we recommend you switch to an alternative crate such as: - [`astral-tokio-tar`](https://crates.io/crates/astral-tokio-tar)
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0No fixed version published yet for tokio-tar. Pin to a known-safe version or switch to an alternative.