Logo
vulnerabilityCVE-2026-58471
Name
CVE-2026-58471
Source
NVD ( link)Debian ( link)
Description
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
wget
Exploitable

Vulnerability Ratings#


6
CVSSv4
5.9
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.25.0
Patched
openwrt
master
1.25.0-r5
Exploitable
openwrt
openwrt-25.12
1.25.0-r3
Exploitable
yocto
kirkstone
1.21.4
Exploitable
yocto
master
1.25.0
Patched
yocto
scarthgap
1.21.4
Exploitable

Resolved with patches#


wget (buildroot:master)

#
Title
Author
Resolve
1
Fix buffer size handling in filename conversion
Arkadi Vainbrand <arkadva8@gmail.com>
CVE-2026-58471

wget (yocto:master)

#
Title
Author
Resolve
1
Fix buffer size handling in filename conversion
Arkadi Vainbrand <arkadva8@gmail.com>
CVE-2026-58471