• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Boustead Singapore cyberattack

    Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit

    WaterPlum

    WaterPlum Hackers Steal $10.7M in Crypto From IT Workers

    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    Contagious Interview, WaterPlum, North Korea

    Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum

    CVE-2026-76460

    Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

    Thinkng Bull Cyberattack

    South Korea Math Academy Hit by Cyberattack, Student Data at Risk

    Iranian cyber actors

    Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    outage communications

    CISA, FBI Urge Clearer Communication During Major Outages

    A session cookie depicted as a key being stolen from a browser window while a two-factor authentication prompt sits bypassed, illustrating Claude session hijacking by infostealer malware.

    Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage

    Social Media Ban

    New Zealand Moves to Ban Social Media for Under-16s

    Prompt Injection, Grok, Grok AI, Gemini, Fraud, Agentic AI, AI-assisted Cyberattacks

    Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen

    India online safety rules

    India Tightens Social Media Rules to Protect Children Online

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Boustead Singapore cyberattack

    Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit

    WaterPlum

    WaterPlum Hackers Steal $10.7M in Crypto From IT Workers

    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    Contagious Interview, WaterPlum, North Korea

    Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum

    CVE-2026-76460

    Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack

    Thinkng Bull Cyberattack

    South Korea Math Academy Hit by Cyberattack, Student Data at Risk

    Iranian cyber actors

    Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    outage communications

    CISA, FBI Urge Clearer Communication During Major Outages

    A session cookie depicted as a key being stolen from a browser window while a two-factor authentication prompt sits bypassed, illustrating Claude session hijacking by infostealer malware.

    Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage

    Social Media Ban

    New Zealand Moves to Ban Social Media for Under-16s

    Prompt Injection, Grok, Grok AI, Gemini, Fraud, Agentic AI, AI-assisted Cyberattacks

    Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen

    India online safety rules

    India Tightens Social Media Rules to Protect Children Online

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cyber News

RCE Vulnerability (CVE-2025-62518) Discovered in Popular Rust Library async-tar and Its Forks

Ashish Khaitan by Ashish Khaitan
October 23, 2025
in Cyber News, Firewall Daily, Vulnerabilities
0
CVE‑2025‑62518
626
SHARES
3.5k
VIEWS
Share on LinkedInShare on Twitter

A critical flaw has been identified in a Rust library that demands immediate attention from developers and IT decision-makers leveraging the Rust ecosystem. The vulnerability, tracked as CVE‑2025‑62518, exposes serious remote code execution (RCE) risks in the widely used async tar library ecosystem. 

The root of the problem lies in a boundary-parsing error within a key Rust component. The library at the center is the async-tar “family” of crates: the original async‑tar library and its many forks, including the popular tokio‑tar and astral‑tokio‑tar. According to vulnerability listings, versions of astral-tokio-tar before 0.5.6 contain the flaw. NVD records confirm it was published on October 21, 2025.  

Researchers at Edera dubbed the vulnerability “TARmageddon” and described it as a boundary-parsing bug in a Rust library that can lead to RCE via file overwriting attacks, such as replacing configuration files or hijacking build back-ends.  

Technical Overview of the CVE‑2025‑62518 Vulnerability 

The issue lies in the inconsistent handling of PAX and ustar headers during TAR-file extraction in the affected Rust library. In some TAR archives, a PAX header may indicate a file size (say X bytes), while the accompanying ustar header incorrectly indicates zero bytes.  

The vulnerable library uses the ustar size (zero) when advancing the stream, failing to skip over the actual file data of the nested archive. As a result, the parser misaligns and treats headers of the nested archive as entries in the outer archive. This misalignment allows for: 

  • File-overwriting attacks during extraction 
  • Supply-chain poisoning via build systems or package managers 
  • Bypassing security scanners or manifest checks by hiding nested archives 

In one example scenario, an attacker crafts a malicious archive such that during extraction via the vulnerable Rust library (in a build or CI system), the hidden inner TAR injects or overwrites files unexpectedly, potentially giving the attacker remote code execution (RCE) privileges. 

Scope & affected ecosystem 

Because tokio-tar has over 5 million downloads and has been used widely (often as an indirect dependency), the blast radius is large. Projects known to be impacted include uv (a Python package manager), testcontainers, and wasmCloud.  

The complexity is worsened by the fact that the most popular fork (tokio‐tar) appears to be unmaintained (“abandonware”), meaning the fix cannot simply be pushed upstream and inherited automatically. 

Disclosure timeline 

The vulnerability disclosure followed a non-standard, decentralized process because of the upstream abandonment. Key dates: 

  • August 21, 2025: Bug discovered by Edera and a minimal repro built. 
  • August 22: Patches created and initial disclosures made to library maintainers and select downstream users under a 60-day embargo (ending October 21). 
  • September 2: Acknowledgment from the upstream async-tar project. 
  • October 21, 2025: Public release of advisory and patches. 

Conclusion  

Organizations using the affected Rust library should act quickly to address CVE-2025-62518, a high-severity RCE vulnerability in the async-tar ecosystem. The safest step is to upgrade to astral-tokio-tar version 0.5.6 or later or migrate away from unmaintained forks like tokio-tar.  

If immediate patching isn’t possible, apply mitigations such as sandboxed extraction, file-size limits, and post-extraction scans, and review dependencies for indirect exposure. The TARmageddon flaw highlights that even Rust’s strong safety features can’t prevent logic bugs. 

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CVE‑2025‑62518RCERust libraryThe Cyber ExpressThe Cyber Express Newstokio
Previous Post

WazirX to Resume Exchange Operations After 15-Month Hiatus Following Cyberattack

Next Post

Microsoft Digital Defense Report 2025: Extortion and Ransomware Lead Global Cybercrime Surge

Next Post
Digital Defense Report

Microsoft Digital Defense Report 2025: Extortion and Ransomware Lead Global Cybercrime Surge

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Boustead Singapore cyberattack
Firewall Daily

Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit

September 21, 2026
WaterPlum
Cyber News

WaterPlum Hackers Steal $10.7M in Crypto From IT Workers

September 21, 2026
weekly roundup September 18 2026
Firewall Daily

The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

September 18, 2026
Contagious Interview, WaterPlum, North Korea
Cyber News

Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum

September 18, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information