Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58469

Опубликовано: 07 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

A flaw was found in GNU Wget. A malicious server could exploit a heap buffer underread vulnerability by providing a specially crafted Metalink document containing a URL with only whitespace characters. This could lead to memory corruption and abnormal program behavior, potentially causing a denial of service.

Отчет

Moderate: A heap-buffer-underread in GNU Wget's clean_metalink_string() function, affecting Red Hat Enterprise Linux 8, can be triggered when wget processes a specially crafted Metalink document containing a resource URL consisting only of whitespace characters. This code path is only reachable when Wget's Metalink support is explicitly requested via --input-metalink or --metalink-over-http; it is not exercised during ordinary downloads. Successful exploitation requires a user to invoke Wget's Metalink handling against an attacker-controlled or compromised server. The out-of-bounds byte is read only to decide whether to continue a trim loop and is never returned, logged, or written -- the practical impact is limited to a crash of the wget process (denial of service), not memory corruption or code execution.

Меры по смягчению последствий

Avoid using Wget's Metalink options (--input-metalink and --metalink-over-http) when downloading from untrusted or unverified servers. Since Metalink processing must be explicitly requested, omitting these options avoids the vulnerable code path entirely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wgetNot affected
Red Hat Enterprise Linux 6wgetNot affected
Red Hat Enterprise Linux 7wgetNot affected
Red Hat Enterprise Linux 9wgetNot affected
Red Hat Enterprise Linux 8wgetFixedRHSA-2026:6214401.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2497838wget: GNU Wget: Memory corruption via crafted Metalink URL

EPSS

Процентиль: 29%
0.00351
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

CVSS3: 7.5
nvd
2 месяца назад

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

msrc
около 1 месяца назад

GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing

CVSS3: 7.5
debian
2 месяца назад

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buff ...

suse-cvrf
около 2 месяцев назад

Security update for wget

EPSS

Процентиль: 29%
0.00351
Низкий

6.5 Medium

CVSS3