Gnu Wget vulnerabilities
26 known vulnerabilities affecting gnu/wget.
Total CVEs
26
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM12LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-58470P4MEDIUMCVSS 5.3≤ 1.25.02026-07-07
CVE-2026-58470 [MEDIUM] CWE-190 CVE-2026-58470: GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronizatio
nvd
CVE-2021-31879P4MEDIUMCVSS 6.1≤ 1.21.12021-04-29
CVE-2021-31879 [MEDIUM] CVE-2021-31879: GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
nvd
CVE-2002-1565P4HIGHCVSS 7.5≥ 0, < 1.8.2-82003-06-16
CVE-2002-1565 [HIGH] CVE-2002-1565: Buffer overflow in url_filename function for wget 1
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
osv
CVE-2002-1344P4MEDIUMCVSS 5.0v1.5.3v1.6+5 more2002-12-18
CVE-2002-1344 [MEDIUM] CVE-2002-1344: Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or ove
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
nvdosv
CVE-2004-1487P4MEDIUMCVSS 5.0v1.8v1.8.1+3 more2005-04-27
CVE-2004-1487 [MEDIUM] CVE-2004-1487: wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirecti
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
nvdosv
CVE-1999-0402P4MEDIUMCVSS 5.0v1.5.31999-01-02
CVE-1999-0402 [MEDIUM] CVE-1999-0402: wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
nvd
← Previous2 / 2