CVE-2026-58471
CVE-2026-58471 is a medium-severity vulnerability in Gnu Wget with a CVSS 3.x base score of 5.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-122.
Key facts
- Severity: Medium (CVSS 3.x base score 5.9)
- CVSS v4: 6.0
- EPSS exploit prediction: 0% (31st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-122
- Affected product: Gnu Wget
- Published:
- Last modified:
Description
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
Frequently asked questions
- What is CVE-2026-58471?
- GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
- How severe is CVE-2026-58471?
- CVE-2026-58471 has a CVSS 3.x base score of 5.9, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity low, and availability high.
- Is CVE-2026-58471 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (31st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-58471?
- CVE-2026-58471 affects Gnu Wget. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-58471?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-58471 published?
- CVE-2026-58471 was published on 2026-07-07 and last updated on 2026-07-09.
References
- https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
- https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c
Affected products (1)
- cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
More vulnerabilities in Gnu Wget
- CVE-2019-5953 — Critical (CVSS 9.8): Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may…
- CVE-2014-4877 — Critical (CVSS 9.3): Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to…
- CVE-2024-38428 — Critical (CVSS 9.1): url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be…
- CVE-2017-13090 — High (CVSS 8.8): The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget…
- CVE-2017-13089 — High (CVSS 8.8): The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the…
- CVE-2016-4971 — High (CVSS 8.8): GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted…
Other CWE-122 (Heap-based Buffer Overflow) vulnerabilities
- CVE-2026-10747 — Critical (CVSS 10.0): IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due…
- CVE-2026-46752 — Critical (CVSS 10.0): Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from…
- CVE-2026-24822 — Critical (CVSS 10.0): Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is…
- CVE-2025-23123 — Critical (CVSS 10.0): A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a…
- CVE-2022-34819 — Critical (CVSS 10.0): A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions <…
- CVE-2026-10858 — Critical (CVSS 9.9): IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or…
Browse all CWE-122 (Heap-based Buffer Overflow) vulnerabilities →