Tarmageddon is a great example of why RUSTSEC tracks unmaintained crates/libraries and why such unmaintained projects are very much security-relevant: edera.dev/stories/tarmageddon
#rust
TARmageddon (CVE-2025-62518): RCE Vulnerability Highlights the Challenges of Open Source Abandonware | Edera Blog
Edera uncovers TARmageddon (CVE-2025-62518), a Rust async-tar RCE flaw exposing the real dangers of open-source abandonware and supply chain security.Edera