CVE-2026-58472
published 2026-07-07CVE-2026-58472: GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that…
PriorityP335high7.1CVSS 3.1
AVNACLPRNUIRSUCNILAH
EPSS
0.22%
12.6th percentile
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | wget | <= 1.25.0 | — |
| gnu | wget | — | — |
| gnuwget | wget | <= 1.25.0 | — |
| ubuntu | wget | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu9.1CRITICAL
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2026-07-14·CVSS 9.1
CVE-2026-58470 [CRITICAL] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)
It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu
26.04 LTS. (CVE-2026-58469)
It was discovered that Wget incorrectly handled Content-Range header
values, leading to an integer overflow. A remote attacker could
pos
Red Hat
wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
vendor_redhat·2026-07-07·CVSS 7.1
CVE-2026-58472 [HIGH] CWE-131 wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the `html_quote_string()` function by providing a specially crafted HTML attribute. This c
VulDB
GNU wget up to 1.25.0 HTML src/convert.c html_quote_string heap-based overflow (EUVD-2026-42084)
vuldb·2026-07-07·CVSS 5.9
CVE-2026-58472 [MEDIUM] GNU wget up to 1.25.0 HTML src/convert.c html_quote_string heap-based overflow (EUVD-2026-42084)
A vulnerability was found in GNU wget up to 1.25.0. It has been rated as critical. This issue affects the function html_quote_string of the file src/convert.c of the component HTML Handler. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2026-58472. The attack is possible to be carried out remotely. No exploit exists.
GHSA
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory cor
ghsa_unreviewed·2026-07-07
CVE-2026-58472 [MEDIUM] CWE-190 GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory cor
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [epel-all]
bugzilla·2026-07-14·CVSS 7.1
CVE-2026-58472 [HIGH] CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [epel-all]
CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocatio
Bugzilla
CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
bugzilla·2026-07-14·CVSS 7.1
CVE-2026-58472 [HIGH] CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocat
Bugzilla
CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
bugzilla·2026-07-14·CVSS 7.1
CVE-2026-58472 [HIGH] CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
CVE-2026-58472 wget2: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocat
Bugzilla
CVE-2026-58472 wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
bugzilla·2026-07-07·CVSS 7.1
CVE-2026-58472 [HIGH] CVE-2026-58472 wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
CVE-2026-58472 wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
2026-07-07
Published