{"id":"GHSA-6gx3-4362-rf54","summary":"astral-tokio-tar insufficiently validates PAX extensions during extraction","details":"## Impact\n\nIn versions 0.5.6 and earlier of astral-tokio-tar, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping (rather than rejection) of invalid PAX extensions could be used as a building block for a parser differential, for example by having astral-tokio-tar silently skip a malformed GNU “long link” extension so that a subsequent parser would misinterpret the extension.\n\nIn practice, exploiting this behavior in astral-tokio-tar requires a secondary misbehaving tar parser, i.e. one that insufficiently validates malformed PAX extensions and interprets them rather than skipping or erroring on them. Consequently this advisory is considered low-severity within astral-tokio-tar itself, as it requires a separate vulnerability against any unrelated tar parser.\n\n## Patches\n\nVersions 0.6.0 and newer of astral-tokio-tar reject invalid PAX extensions, rather than silently skipping them. \n\n## Workarounds\n\nUsers are advised to upgrade to version 0.6.0 or newer to address this advisory.\n\nMost users should experience no breaking changes as a result of the patch above. Some users who attempt to extract poorly constructed tar files may experience errors; users should re-construct their tar files with a conforming tar parser.\n\n## Attribution\n\n- Sergei Zimmerman (@xokdvium)","aliases":["CVE-2026-32766","RUSTSEC-2026-0066"],"modified":"2026-09-10T03:50:37.790948185Z","published":"2026-03-17T19:49:35Z","database_specific":{"cwe_ids":["CWE-436"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-17T19:49:35Z","nvd_published_at":"2026-03-20T00:16:18Z"},"references":[{"type":"WEB","url":"https://github.com/astral-sh/tokio-tar/security/advisories/GHSA-6gx3-4362-rf54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32766"},{"type":"WEB","url":"https://github.com/astral-sh/tokio-tar/commit/e5e0139cae4577eeedf5fc16b65e690bf988ce52"},{"type":"PACKAGE","url":"https://github.com/astral-sh/tokio-tar"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0066.html"}],"affected":[{"package":{"name":"astral-tokio-tar","ecosystem":"crates.io","purl":"pkg:cargo/astral-tokio-tar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.5.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6gx3-4362-rf54/GHSA-6gx3-4362-rf54.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}