CVE-2026-58471

Name
CVE-2026-58471
Description
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:* wget >= None <= 1.25.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wget edge-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget edge-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget edge-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget edge-main 1.20.3-r0 None possibly vulnerable
wget edge-main 1.20.1-r0 None possibly vulnerable
wget edge-main 1.19.5-r0 None possibly vulnerable
wget edge-main 1.19.2-r0 None possibly vulnerable
wget edge-main 1.19.1-r1 None possibly vulnerable
wget 3.24-main 1.25.0-r3 Jingyun Hua <huajingyun@loongson.cn> possibly vulnerable
wget 3.23-main 1.25.0-r2 Celeste <cielesti@protonmail.com> possibly vulnerable
wget 3.22-main 1.25.0-r1 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.22-main 1.25.0-r0 None possibly vulnerable
wget 3.22-main 1.20.3-r0 None possibly vulnerable
wget 3.22-main 1.20.1-r0 None possibly vulnerable
wget 3.22-main 1.19.5-r0 None possibly vulnerable
wget 3.22-main 1.19.2-r0 None possibly vulnerable
wget 3.22-main 1.19.1-r1 None possibly vulnerable
wget 3.21-main 1.25.0-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.21-main 1.20.3-r0 None possibly vulnerable
wget 3.21-main 1.20.1-r0 None possibly vulnerable
wget 3.21-main 1.19.5-r0 None possibly vulnerable
wget 3.21-main 1.19.2-r0 None possibly vulnerable
wget 3.21-main 1.19.1-r1 None possibly vulnerable
wget 3.20-main 1.24.5-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.20-main 1.20.3-r0 None possibly vulnerable
wget 3.20-main 1.20.1-r0 None possibly vulnerable
wget 3.20-main 1.19.5-r0 None possibly vulnerable
wget 3.20-main 1.19.2-r0 None possibly vulnerable
wget 3.20-main 1.19.1-r1 None possibly vulnerable
wget 3.19-main 1.21.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> possibly vulnerable
wget 3.19-main 1.20.3-r0 None possibly vulnerable
wget 3.19-main 1.20.1-r0 None possibly vulnerable
wget 3.19-main 1.19.5-r0 None possibly vulnerable
wget 3.19-main 1.19.2-r0 None possibly vulnerable
wget 3.19-main 1.19.1-r1 None possibly vulnerable