Astral A.I CyberSecurity Scoring
Astral
Company Information
Website:https://astral.sh
Employees number:32
Number of followers:4,128
NAICS:5112
Industry Type:Software Development
Homepage:astral.sh
Astral Risk Score (AI oriented)
Between 700 and 749
AstralSoftware Development
Updated:
02/04/2026
02/04/2026
749/1000
Moderate
Ba
Astral Global Score (TPRM)
xxxx
AstralSoftware Development
Score locked

AstralModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
748
JULY 2025
748
JUNE 2025
750
Vulnerability
16 Jun 2025 • Astral
Astral
TARmageddon Vulnerability (CVE-2025-62518) in async-tar and tokio-tar Libraries
748
CRITICAL-2
AST4632346102325
A critical vulnerability named TARmageddon (CVE-2025-62518) was discovered in the async-tar Rust library and its forks, including tokio-tar, which is widely used in Python and web development ecosystems. The flaw, with a CVSS score of 8.1 (High), allows remote code execution via malicious nested TAR archives, enabling attackers to overwrite configuration files and hijack build backends. Astral’s uv package manager, testcontainers, and wasmCloud were among the affected projects. The vulnerability stems from a desynchronization flaw in TAR parsing, where mismatched PAX and ustar headers cause the parser to incorrectly merge hidden malicious payloads with legitimate files. This enables Python build backend hijacking, container image poisoning, and bypassing security scans. While patches were released for active forks (e.g., astral-tokio-tar), the original tokio-tar (5M+ downloads) remains unpatched, leaving downstream users exposed unless they migrate. The incident highlights risks from abandoned open-source projects and the need for proactive dependency management. Astral took over maintenance of astral-tokio-tar as the recommended fix, but unpatched systems remain vulnerable to supply-chain attacks, CI/CD compromises, and malicious package distribution.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Astral ??
What was Astral's A.I Rankiteo Cyber Score in May 2026 ??
What was Astral's A.I Rankiteo Cyber Score in April 2026 ??
What was Astral's A.I Rankiteo Cyber Score in March 2026 ??
What was Astral's A.I Rankiteo Cyber Score in February 2026 ??
What was Astral's A.I Rankiteo Cyber Score in January 2026 ??
What was Astral's A.I Rankiteo Cyber Score in December 2025 ??
What was Astral's A.I Rankiteo Cyber Score in November 2025 ??
What was Astral's A.I Rankiteo Cyber Score in October 2025 ??
What was Astral's A.I Rankiteo Cyber Score in September 2025 ??
What was Astral's A.I Rankiteo Cyber Score in August 2025 ??
What was Astral's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Astral's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Astral ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Astral's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?