Async Rust Tar Archive Library Vulnerability in Astral Technologies
CVE-2026-32766
1.7LOW
What is CVE-2026-32766?
The astral-tokio-tar library, utilized for asynchronous reading and writing of tar archives in Rust, has a vulnerability in versions 0.5.6 and earlier, where malformed PAX extensions are silently ignored during the parsing of tar archives. This behavior can lead to unintended consequences, particularly when paired with other tar parsers that do not adequately validate PAX extensions. Such parsers may misinterpret the skipped extensions, which can be exploited in certain scenarios. This issue has been addressed in version 0.6.0, enhancing the library's security by ensuring that invalid extensions are properly rejected.
Affected Version(s)
tokio-tar < 0.6.0
