Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.
🚨 HIGH - Wget Metalink whitespace URL heap buffer underread (CVE-2026-58469)
GNU Wget through 1.25.0 is vulnerable to a heap buffer underread in clean_metalink_string() within src/metalink.c when processing Metalink documents. The root cause is a pointer underflow/heap buffer underread triggered by improper handling of whitespace-only URLs, where the code decrements a pointer past the start of the allocated buffer. Exploitation is remote: an attacker-controlled or malicious server can serve a crafted Metalink file and trigger the flaw when a victim uses wget against that Metalink content, with no special privileges beyond inducing the fetch. Impact ranges from memory corruption and abnormal behavior to a reliable denial of service (crash), and should be treated as potentially exploitable memory-safety risk.
👉 Affected: wget <= 1.25.0 | Upgrade to No fix yet - treat as suspicious
Post summary
CVE-2026-58469 is a heap buffer underread in GNU Wget triggered by whitespace-only URLs in Metalink files, enabling remote denial‑of‑service; no patch is available yet.