PT-2026-56238 · Gnu+3 · Wget+3

·

CVE-2026-58469

·

Published

2026-07-07

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GNU Wget versions prior to 1.25.1
Description A heap buffer underread exists in the clean metalink string() function within src/metalink.c. This occurs when the software processes a Metalink document containing a URL consisting only of whitespace. A malicious server can trigger this by serving a crafted Metalink file, causing the function to decrement a pointer past the start of the allocated buffer. This memory corruption can lead to abnormal program behavior or a denial of service resulting in a crash.
Recommendations Update GNU Wget to the version containing commit 37a40fc.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:62144
CVE-2026-58469
ECHO-019F-ED29-0163
JLSEC-2026-1158
OESA-2026-3152
OPENSUSE-SU-2026:11252-1
OPENSUSE-SU-2026:21665-1
RHSA-2026:62144
SUSE-SU-2026:23053-1
SUSE-SU-2026:23163-1
SUSE-SU-2026:23297-1
SUSE-SU-2026:23326-1
SUSE-SU-2026:3148-1
SUSE-SU-2026:3206-1
SUSE-SU-2026:3337-1
USN-8543-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Wget