Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:cargo/astral-sh/tokio-tar

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-32766 is a low-severity vulnerability in the astral-tokio-tar Rust library versions prior to 0.6.0. The issue arises from the library silently skipping malformed PAX extensions in tar archives instead of rejecting them. This behavior can enable a parser differential attack when combined with another tar parser that misinterprets these malformed extensions. Exploitation requires a secondary vulnerability in an unrelated tar parser, making this a complex, multi-step attack. No known exploits are currently reported in the wild. The vulnerability affects asynchronous Rust applications using astral-tokio-tar for tar archive processing. It has been fixed in version 0.6.

Join the discussion

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:cargo/astral-sh/tokio-tar
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses