CVE-2026-58470

Name
CVE-2026-58470
Description
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* wget >= None <= 1.25.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wget edge-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget edge-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget edge-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.20.3-r0 None possibly vulnerable
wget edge-main 1.20.1-r0 None possibly vulnerable
wget edge-main 1.19.5-r0 None possibly vulnerable
wget edge-main 1.19.2-r0 None possibly vulnerable
wget edge-main 1.19.1-r1 None possibly vulnerable
wget 3.24-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget 3.23-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget 3.22-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.22-main 1.25.0-r0 None possibly vulnerable
wget 3.22-main 1.20.3-r0 None possibly vulnerable
wget 3.22-main 1.20.1-r0 None possibly vulnerable
wget 3.22-main 1.19.5-r0 None possibly vulnerable
wget 3.22-main 1.19.2-r0 None possibly vulnerable
wget 3.22-main 1.19.1-r1 None possibly vulnerable
wget 3.21-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.21-main 1.20.3-r0 None possibly vulnerable
wget 3.21-main 1.20.1-r0 None possibly vulnerable
wget 3.21-main 1.19.5-r0 None possibly vulnerable
wget 3.21-main 1.19.2-r0 None possibly vulnerable
wget 3.21-main 1.19.1-r1 None possibly vulnerable
wget 3.20-main 1.24.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.20-main 1.20.3-r0 None possibly vulnerable
wget 3.20-main 1.20.1-r0 None possibly vulnerable
wget 3.20-main 1.19.5-r0 None possibly vulnerable
wget 3.20-main 1.19.2-r0 None possibly vulnerable
wget 3.20-main 1.19.1-r1 None possibly vulnerable
wget 3.19-main 1.21.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.19-main 1.20.3-r0 None possibly vulnerable
wget 3.19-main 1.20.1-r0 None possibly vulnerable
wget 3.19-main 1.19.5-r0 None possibly vulnerable
wget 3.19-main 1.19.2-r0 None possibly vulnerable
wget 3.19-main 1.19.1-r1 None possibly vulnerable