{"id":"GHSA-fp55-jw48-c537","aliases":["RUSTSEC-2026-0112"],"url":"https://o3.security/vulnerability/GHSA-fp55-jw48-c537","summary":"astral-tokio-tar is Vulnerable to PAX Header Desynchronization","details":"### Impact\n\nVersions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle unexpected files onto a victim's filesystem.\n\nSee GHSA-j5gw-2vrg-8fgx for a similar desynchronization bug in astral-tokio-tar.\n\n### Patches\n\nVersions 0.6.1 and newer of astral-tokio-tar address this differential.\n\n### Workarounds\n\nUsers are advised to upgrade to version 0.6.1 or newer to address this advisory.\n\nThere is no workaround other than upgrading. Users should experience no breaking changes as a result of the upgrade.\n\n### Resources\n\n- GHSA-j5gw-2vrg-8fgx is a similar PAX desynchronization bug\n\n### Attribution\n\n- Reporter: Adam Harvey (@lawngnome)","published":"2026-05-06T17:26:12Z","modified":"2026-09-10T03:50:46.705838044Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"astral-tokio-tar","fixedVersion":"0.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/astral-sh/tokio-tar/security/advisories/GHSA-fp55-jw48-c537"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fp55-jw48-c537"},{"type":"PACKAGE","url":"https://github.com/astral-sh/tokio-tar"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0112.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:46.705838044Z"}}