Gnu Wget vulnerabilities
27 known vulnerabilities affecting gnu/wget.
Total CVEs
27
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM13LOW1
Vulnerabilities
Page 2 of 2
CVE-2026-16599P4MEDIUMCVSS 5.1≤ 1.25.02026-08-25
CVE-2026-16599 [MEDIUM] CWE-606 CVE-2026-16599: GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a cra
nvd
CVE-2026-58470P4MEDIUMCVSS 5.3≤ 1.25.02026-07-07
CVE-2026-58470 [MEDIUM] CWE-190 CVE-2026-58470: GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronizatio
nvd
CVE-2021-31879P4MEDIUMCVSS 6.1≤ 1.21.12021-04-29
CVE-2021-31879 [MEDIUM] CVE-2021-31879: GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
nvd
CVE-2002-1565P4HIGHCVSS 7.5≥ 0, < 1.8.2-82003-06-16
CVE-2002-1565 [HIGH] CVE-2002-1565: Buffer overflow in url_filename function for wget 1
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
osv
CVE-2002-1344P4MEDIUMCVSS 5.0v1.5.3v1.6+5 more2002-12-18
CVE-2002-1344 [MEDIUM] CVE-2002-1344: Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or ove
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
nvdosv
CVE-2004-1487P4MEDIUMCVSS 5.0v1.8v1.8.1+3 more2005-04-27
CVE-2004-1487 [MEDIUM] CVE-2004-1487: wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirecti
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
nvdosv
CVE-1999-0402P4MEDIUMCVSS 5.0v1.5.31999-01-02
CVE-1999-0402 [MEDIUM] CVE-1999-0402: wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
nvd
← Previous2 / 2