Going public today is CVE-2025-62518, or better known by the name given by the security researchers involved: TARmageddon. The TARmageddon vulnerability affects the popular async-tar Rust library and its various forks like tokio-tar. In turn TARmageddon impacts the uv Python package manager and other users of this library.

Edera made public today their discovery of a critical boundary-parsing bug in the async-tar Rust library and downstream forks like tokio-tar. TARmageddon is rated as a “high” severity bug and can lead to remote code execution through file overwriting attacks.

  • Qwel
    link
    fedilink
    arrow-up
    5
    ·
    4 months ago

    Someone should train an llm on these guys

    • MadhuGururajan@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      god no. some of the comments are so misinformed that i wonder whether they are actual software people at all.

      No language can catch a logic bug.