Gnu Wget2 vulnerabilities
3 known vulnerabilities affecting gnu/wget2.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-69194P3CRITICALCVSS 9.8fixed in 2.2.12026-01-09
CVE-2025-69194 [CRITICAL] CWE-22 CVE-2025-69194: A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails
A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment.
nvdosv
CVE-2025-69195P3HIGHCVSS 8.8≥ 2.1.0, < 2.2.12026-01-09
CVE-2025-69195 [HIGH] CWE-121 CVE-2025-69195: A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the file
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead
nvdosv
CVE-2026-1858P4MEDIUMCVSS 4.8≤ 2.2.12026-04-29
CVE-2026-1858 [MEDIUM] CWE-20 CVE-2026-1858: wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
nvd