CVE-2026-58469Disclosure(gnu / wget)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wget

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wget

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-08-01: 1Technical Details · 2026-07-08: 107-0808-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-08-011
General1
Full discourse2 posts
  • IntegSec@integ_sec
    General

    CVE-2026-58469: GNU Wget Metalink Processing Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04rztmm0

    Post summary

    The snippet alerts to CVE-2026-58469 with an associated link but provides no further technical, exploit, or patch details.

    0000054
    32 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Wget Metalink whitespace URL heap buffer underread (CVE-2026-58469) GNU Wget through 1.25.0 is vulnerable to a heap buffer underread in clean_metalink_string() within src/metalink.c when processing Metalink documents. The root cause is a pointer underflow/heap buffer underread triggered by improper handling of whitespace-only URLs, where the code decrements a pointer past the start of the allocated buffer. Exploitation is remote: an attacker-controlled or malicious server can serve a crafted Metalink file and trigger the flaw when a victim uses wget against that Metalink content, with no special privileges beyond inducing the fetch. Impact ranges from memory corruption and abnormal behavior to a reliable denial of service (crash), and should be treated as potentially exploitable memory-safety risk. 👉 Affected: wget <= 1.25.0 | Upgrade to No fix yet - treat as suspicious

    Post summary

    CVE-2026-58469 is a heap buffer underread in GNU Wget triggered by whitespace-only URLs in Metalink files, enabling remote denial‑of‑service; no patch is available yet.

    0000072
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuwget---

Explore more