Integer Overflow or Wraparound Affecting wget package, versions <1.25.0-r15


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-WGET-18968941
  • published20 Aug 2026
  • disclosed7 Jul 2026

Introduced: 7 Jul 2026

CVE-2026-58472  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

Upgrade Wolfi wget to version 1.25.0-r15 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVSS Base Scores

version 3.1