CVE-2026-58469

NameCVE-2026-58469
DescriptionGNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1141689

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wget (PTS)bullseye1.21-1+deb11u1vulnerable
bullseye (security)1.21-1+deb11u2vulnerable
bookworm1.21.3-1+deb12u1vulnerable
forky, trixie1.25.0-2vulnerable
sid1.25.0-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wgetsource(unstable)(unfixed)1141689

Notes

[trixie] - wget <no-dsa> (Minor issue)
[bookworm] - wget <postponed> (Minor issue)
[bullseye] - wget <postponed> (Minor issue)
Fixed by: https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826

Search for package or bug name: Reporting problems