mediumVulnerability

GHSA-fp55-jw48-c537

### Impact Versions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle unexpected files onto a victim's filesystem. See GHSA-j5gw-2vrg-8fgx for a similar desynchronization bug in astral-tokio-tar. ### Patches Versions 0.6.1 and newer of astral-tokio-tar address this differential. ### Workarounds Users are advised to upgrade to version 0.6.1 or newer to address this advisory. There is no workaround other than upgrading. Users should experience no breaking changes as a result of the upgrade. ### Resources - GHSA-j5gw-2vrg-8fgx is a similar PAX desynchronization bug ### Attribution - Reporter: Adam Harvey (@lawngnome)

Properties

ghsa_id
GHSA-fp55-jw48-c537
severity
medium
summary
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
cve_id
GHSA-fp55-jw48-c537
is_ghsa_only
true
ghsa_published
2026-05-06T17:26:12Z
source_url
https://github.com/advisories/GHSA-fp55-jw48-c537
ghsa_updated
2026-05-06T17:26:13Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]rust/astral-tokio-tar

AFFECTS (1)

[Software]rust/astral-tokio-tar

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-fp55-jw48-c537 — Ninja Signal Threat Intelligence | Ninja Signal