GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
{
"sources": [
{
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58471",
"modified": "2026-07-09T16:02:07.273Z",
"imported": "2026-08-03T20:01:18.307Z",
"published": "2026-07-07T21:17:28.710Z",
"id": "CVE-2026-58471",
"database_specific": {
"status": "Analyzed"
},
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58471"
},
{
"url": "https://api.github.com/advisories/GHSA-vv88-699v-w5rh",
"html_url": "https://github.com/advisories/GHSA-vv88-699v-w5rh",
"imported": "2026-08-03T20:01:21.687Z",
"published": "2026-07-07T21:31:36Z",
"id": "GHSA-vv88-699v-w5rh",
"modified": "2026-07-07T21:31:43Z"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42083",
"modified": "2026-07-14T22:03:12Z",
"imported": "2026-08-03T20:01:19.724Z",
"published": "2026-07-07T19:47:47Z",
"id": "EUVD-2026-42083",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-42083"
}
],
"license": "CC-BY-4.0"
}