Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Astral

Astral Vendor Cyber Rating & Cyber Score

astral.sh

Astral builds high-performance developer tools for the Python ecosystem, including uv (an all-in-one Python package and project manager) and Ruff (an extremely fast Python linter and formatter).


Astral A.I CyberSecurity Scoring

Astral
Company Information
Website:https://astral.sh
Employees number:32
Number of followers:4,128
NAICS:5112
Industry Type:Software Development
Homepage:astral.sh
Astral Risk Score (AI oriented)
Between 700 and 749
logo
AstralSoftware Development
Updated:
02/04/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Astral Global Score (TPRM)
xxxx
logo
AstralSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Astral
AstralModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
749Before Incident
AUGUST 2025
748Before Incident
JULY 2025
748Before Incident
JUNE 2025
750Before Incident
Vulnerability
16 Jun 2025Astral
Astral

TARmageddon Vulnerability (CVE-2025-62518) in async-tar and tokio-tar Libraries

748After Incident
CRITICAL-2
AST4632346102325
A critical vulnerability named TARmageddon (CVE-2025-62518) was discovered in the async-tar Rust library and its forks, including tokio-tar, which is widely used in Python and web development ecosystems. The flaw, with a CVSS score of 8.1 (High), allows remote code execution via malicious nested TAR archives, enabling attackers to overwrite configuration files and hijack build backends. Astral’s uv package manager, testcontainers, and wasmCloud were among the affected projects. The vulnerability stems from a desynchronization flaw in TAR parsing, where mismatched PAX and ustar headers cause the parser to incorrectly merge hidden malicious payloads with legitimate files. This enables Python build backend hijacking, container image poisoning, and bypassing security scans. While patches were released for active forks (e.g., astral-tokio-tar), the original tokio-tar (5M+ downloads) remains unpatched, leaving downstream users exposed unless they migrate. The incident highlights risks from abandoned open-source projects and the need for proactive dependency management. Astral took over maintenance of astral-tokio-tar as the recommended fix, but unpatched systems remain vulnerable to supply-chain attacks, CI/CD compromises, and malicious package distribution.
INCIDENT DETAILS -
TYPE
VulnerabilitySupply Chain AttackLogic Bug
IMPACT
Developer machines (via PyPI package installation)CI/CD pipelinesTestcontainers environmentswasmCloud deploymentsDownstream projects using tokio-tar (5M+ instances)Decentralized disclosure coordination challengesManual patching/migration required for unmaintained forksRisk of supply chain compromise via PyPI/testcontainersErosion of trust in Rust ecosystem securityHighlighted risks of abandonware in critical dependencies
DATA BREACH
Configuration filesBuild backend scriptsHidden payloads in inner TAR archives

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Astral ?
?
What was Astral's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Astral's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Astral's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Astral's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Astral's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Astral's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Astral's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Astral's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Astral's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Astral's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Astral's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Astral's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Astral ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Astral's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?