CVE-2026-58471
published 2026-07-07CVE-2026-58471: GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows…
PriorityP337high7.1CVSS 3.1
AVNACLPRNUIRSUCNILAH
EPSS
0.22%
12.6th percentile
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | wget | <= 1.25.0 | — |
| gnu | wget | — | — |
| gnuwget | wget | <= 1.25.0 | — |
| ubuntu | wget | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu9.1CRITICAL
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2026-07-14·CVSS 9.1
CVE-2026-58470 [CRITICAL] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)
It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu
26.04 LTS. (CVE-2026-58469)
It was discovered that Wget incorrectly handled Content-Range header
values, leading to an integer overflow. A remote attacker could
pos
Red Hat
wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
vendor_redhat·2026-07-07·CVSS 7.1
CVE-2026-58471 [HIGH] CWE-122 wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the convert_fname() function. This occurs when processing a server-supplied filename that requires charac
VulDB
GNU wget up to 1.25.0 Character Set Converter src/url.c convert_fname heap-based overflow (EUVD-2026-42083)
vuldb·2026-07-07·CVSS 5.9
CVE-2026-58471 [MEDIUM] GNU wget up to 1.25.0 Character Set Converter src/url.c convert_fname heap-based overflow (EUVD-2026-42083)
A vulnerability was found in GNU wget up to 1.25.0. It has been declared as critical. This vulnerability affects the function convert_fname of the file src/url.c of the component Character Set Converter. Such manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-58471. The attack can be executed remotely. There is not any exploit available.
GHSA
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corrupti
ghsa_unreviewed·2026-07-07
CVE-2026-58471 [MEDIUM] CWE-122 GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corrupti
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
bugzilla·2026-07-13·CVSS 7.1
CVE-2026-58471 [HIGH] CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be explo
Bugzilla
CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
bugzilla·2026-07-09·CVSS 7.1
CVE-2026-58471 [HIGH] CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be explo
Bugzilla
CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [epel-all]
bugzilla·2026-07-09·CVSS 7.1
CVE-2026-58471 [HIGH] CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [epel-all]
CVE-2026-58471 wget2: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploit
Bugzilla
CVE-2026-58471 wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
bugzilla·2026-07-07·CVSS 7.1
CVE-2026-58471 [HIGH] CVE-2026-58471 wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
CVE-2026-58471 wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
2026-07-07
Published