TARmageddon Strikes: High Profile Security Vulnerability In Popular Rust Library
([Programming] 21 October 10:38 AM EDT
TARmageddon)
Going public today is CVE-2025-62518, or better known by the name given by the security researchers involved: TARmageddon. The TARmageddon vulnerability affects the popular async-tar Rust library and its various forks like tokio-tar. In turn TARmageddon impacts the uv Python package manager and other users of this library.