PT-2026-56241 · Gnu+3 · Wget+3

·

CVE-2026-58472

·

Published

2026-07-07

·

Updated

2026-09-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Wget versions prior to 1.25.0 commit dd692d9
Description A heap buffer overflow occurs in the html quote string() function within src/convert.c. A remote attacker can trigger memory corruption by providing a crafted HTML attribute containing a large number of characters that require entity encoding. This causes a signed integer counter to overflow during the accumulation of the output size, leading to an undersized heap allocation and a subsequent buffer overflow during the copy phase.
Recommendations Update GNU Wget to the version containing commit dd692d9.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:62142
ALSA-2026:62143
ALSA-2026:62144
CVE-2026-58472
ECHO-3772-079F-C642
JLSEC-2026-1161
OESA-2026-3152
OPENSUSE-SU-2026:11252-1
OPENSUSE-SU-2026:21665-1
SUSE-SU-2026:23053-1
SUSE-SU-2026:23163-1
SUSE-SU-2026:23297-1
SUSE-SU-2026:23326-1
SUSE-SU-2026:3148-1
SUSE-SU-2026:3205-1
SUSE-SU-2026:3206-1
USN-8543-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Wget