cbcvebase.
CVE-2025-69195
published 2026-01-09

CVE-2025-69195: A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled…

PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.29%
21.0th percentile
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead to memory corruption. This can cause the application to crash and potentially allow for further malicious activities.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianwget2< wget2 2.2.0+ds-3 (forky)wget2 2.2.0+ds-3 (forky)
gnuwget2>= 0 < 2.2.0+ds-1+deb13u12.2.0+ds-1+deb13u1
gnuwget2>= 0 < 2.2.0+ds-32.2.0+ds-3
gnuwget2>= 2.1.0 < 2.2.12.2.1
msrcazl3_wget_2.1.0-6_on_azure_linux_3.0
msrcazl3_wget_2.1.0-7_on_azure_linux_3.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian7.6LOW
vendor_msrc7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.