Async Rust Tar Archive Library Vulnerability in Astral Technologies
CVE-2026-32766

1.7LOW

Key Information:

Vendor

Astral-sh

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-32766?

The astral-tokio-tar library, utilized for asynchronous reading and writing of tar archives in Rust, has a vulnerability in versions 0.5.6 and earlier, where malformed PAX extensions are silently ignored during the parsing of tar archives. This behavior can lead to unintended consequences, particularly when paired with other tar parsers that do not adequately validate PAX extensions. Such parsers may misinterpret the skipped extensions, which can be exploited in certain scenarios. This issue has been addressed in version 0.6.0, enhancing the library's security by ensuring that invalid extensions are properly rejected.

Affected Version(s)

tokio-tar < 0.6.0

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.