Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-32766 is a low-severity vulnerability in the astral-tokio-tar Rust library versions prior to 0.6.0. The issue arises from the library silently skipping malformed PAX extensions in tar archives instead of rejecting them. This behavior can enable a parser differential attack when combined with another tar parser that misinterprets these malformed extensions. Exploitation requires a secondary vulnerability in an unrelated tar parser, making this a complex, multi-step attack. No known exploits are currently reported in the wild. The vulnerability affects asynchronous Rust applications using astral-tokio-tar for tar archive processing. It has been fixed in version 0.6. Join the discussion | CVE Database V5 | 03/20/2026, 00:07:36 UTC Added: 03/20/2026, 00:09:23 UTC |
0 astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds. Join the discussion | CVE Database V5 | 10/21/2025, 16:13:02 UTC Added: 10/21/2025, 16:28:16 UTC |
Showing 1 to 2 of 2 results