Edera, the security company focused on hardened container runtime security for Kubernetes and AI workloads, has uncovered a new, nasty Rust vulnerability.
Dubbed TARmageddon (CVE-2025-62518), this is a critical flaw in the tokio-tar library and its forks. This potentially allows remote code execution (RCE) across a range of widely used software programs, including Astral’s uv Python package manager and wasmCloud. Other programs almost certainly have vulnerable code hidden inside them as well. With a Common Vulnerability Scoring System…








