Gnuwget Wget vulnerabilities
4 known vulnerabilities affecting gnuwget/wget.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-58469P3HIGHCVSS 7.5≤ 1.25.02026-07-07
CVE-2026-58469 [HIGH] CWE-125 CVE-2026-58469: GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start
nvd
CVE-2026-58471P3HIGHCVSS 7.1≤ 1.25.02026-07-07
CVE-2026-58471 [HIGH] CWE-122 CVE-2026-58471: GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in t
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallo
nvd
CVE-2026-58472P3HIGHCVSS 7.1≤ 1.25.02026-07-07
CVE-2026-58472 [HIGH] CWE-190 CVE-2026-58472: GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in t
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a sign
nvd
CVE-2026-58470P4MEDIUMCVSS 5.3≤ 1.25.02026-07-07
CVE-2026-58470 [MEDIUM] CWE-190 CVE-2026-58470: GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronizatio
nvd