CVE-2026-58469

Name
CVE-2026-58469
Description
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* wget >= None <= 1.25.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wget edge-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget edge-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget edge-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.20.3-r0 None possibly vulnerable
wget edge-main 1.20.1-r0 None possibly vulnerable
wget edge-main 1.19.5-r0 None possibly vulnerable
wget edge-main 1.19.2-r0 None possibly vulnerable
wget edge-main 1.19.1-r1 None possibly vulnerable
wget 3.24-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget 3.23-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget 3.22-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.22-main 1.25.0-r0 None possibly vulnerable
wget 3.22-main 1.20.3-r0 None possibly vulnerable
wget 3.22-main 1.20.1-r0 None possibly vulnerable
wget 3.22-main 1.19.5-r0 None possibly vulnerable
wget 3.22-main 1.19.2-r0 None possibly vulnerable
wget 3.22-main 1.19.1-r1 None possibly vulnerable
wget 3.21-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.21-main 1.20.3-r0 None possibly vulnerable
wget 3.21-main 1.20.1-r0 None possibly vulnerable
wget 3.21-main 1.19.5-r0 None possibly vulnerable
wget 3.21-main 1.19.2-r0 None possibly vulnerable
wget 3.21-main 1.19.1-r1 None possibly vulnerable
wget 3.20-main 1.24.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.20-main 1.20.3-r0 None possibly vulnerable
wget 3.20-main 1.20.1-r0 None possibly vulnerable
wget 3.20-main 1.19.5-r0 None possibly vulnerable
wget 3.20-main 1.19.2-r0 None possibly vulnerable
wget 3.20-main 1.19.1-r1 None possibly vulnerable
wget 3.19-main 1.21.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.19-main 1.20.3-r0 None possibly vulnerable
wget 3.19-main 1.20.1-r0 None possibly vulnerable
wget 3.19-main 1.19.5-r0 None possibly vulnerable
wget 3.19-main 1.19.2-r0 None possibly vulnerable
wget 3.19-main 1.19.1-r1 None possibly vulnerable