Junglewise Threat Intelligence

CVE-2025-62518: RUSTSEC-2025-0110 - astral-tokio-tar Vulnerable to PAX Header Desynchronization

CVE-2025-62518 · Severity: low · CVSS 3.1 · Published 2025-10-21

Technologies: astral-tokio-tar (crates.io). Vendors: crates.io.

Executive brief

astral-tokio-tar Vulnerable to PAX Header Desynchronization

Affected products

  • crates.io astral-tokio-tar
  • crates.io tokio-tar

Related threats