CVE-2026-58470
published 2026-07-07CVE-2026-58470: GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.25%
15.9th percentile
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | wget | <= 1.25.0 | — |
| gnu | wget | — | — |
| gnuwget | wget | <= 1.25.0 | — |
| ubuntu | wget | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu9.1CRITICAL
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2026-07-14·CVSS 9.1
CVE-2026-58470 [CRITICAL] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)
It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu
26.04 LTS. (CVE-2026-58469)
It was discovered that Wget incorrectly handled Content-Range header
values, leading to an integer overflow. A remote attacker could
pos
Red Hat
wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
vendor_redhat·2026-07-07·CVSS 5.3
CVE-2026-58470 [MEDIUM] CWE-190 wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
An integer overflow in GNU Wget's parse_content_range() function allows malicious servers to send crafted Content-Range headers. This triggers undefined behavior and download desynchronization, potentially causing a denial of service or data integrity issues for the client.
Statement: Moderate: GNU Wget is vulnerable t
GHSA
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signe
ghsa_unreviewed·2026-07-07
CVE-2026-58470 [MEDIUM] CWE-190 GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signe
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
VulDB
GNU wget up to 1.25.0 src/http.c parse_content_range integer overflow
vuldb·2026-07-07·CVSS 5.3
CVE-2026-58470 [MEDIUM] GNU wget up to 1.25.0 src/http.c parse_content_range integer overflow
A vulnerability identified as critical has been detected in GNU wget up to 1.25.0. The affected element is the function parse_content_range of the file src/http.c. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2026-58470. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
bugzilla·2026-07-14·CVSS 5.3
CVE-2026-58470 [MEDIUM] CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
Bugzilla
CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [epel-all]
bugzilla·2026-07-14·CVSS 5.3
CVE-2026-58470 [MEDIUM] CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [epel-all]
CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
Bugzilla
CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
bugzilla·2026-07-14·CVSS 5.3
CVE-2026-58470 [MEDIUM] CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
CVE-2026-58470 wget2: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
Bugzilla
CVE-2026-58470 wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
bugzilla·2026-07-07·CVSS 5.3
CVE-2026-58470 [MEDIUM] CVE-2026-58470 wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
CVE-2026-58470 wget: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
2026-07-07
Published