Astral maintains a focused set of developer-oriented tools, including the uv package manager and tokio-tar archive handling library, which serve the Rust ecosystem. The observed vulnerabilities cluster around input validation and parsing correctness issues, reflecting the complexity of handling untrusted data formats in these tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Astral over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13327MEDIUM A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Pack | Feb 27, 2026 | 6.3 | 22 | NO | NO |
CVE-2026-32766MEDIUM astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. T | Mar 20, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Astral.
Media articles that mention a CVE ID that affects a product developed by Astral — matched by CVE ID, not by vendor name.