PT-2026-56239 · Gnu+2 · Wget+2

·

CVE-2026-58470

·

Published

2026-07-07

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Wget versions prior to 1.25.0 commit 43d3ba9
Description An integer overflow occurs in the parse content range() function within src/http.c. This issue allows server-controlled values to cause signed integer arithmetic to overflow. An attacker can provide malicious values in the Content-Range header to trigger undefined behavior and download desynchronization in the client.
Recommendations Update GNU Wget to the version containing commit 43d3ba9.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58470
ECHO-18F1-7A81-EB45
JLSEC-2026-1159
OESA-2026-3152
OPENSUSE-SU-2026:11252-1
OPENSUSE-SU-2026:21665-1
SUSE-SU-2026:23053-1
SUSE-SU-2026:23163-1
SUSE-SU-2026:23297-1
SUSE-SU-2026:23326-1
SUSE-SU-2026:3148-1
SUSE-SU-2026:3205-1
SUSE-SU-2026:3206-1
USN-8543-1

Affected Products

Linuxmint
Ubuntu
Wget