Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2026-58471 — wget

CVE-2026-58471 is a remote code execution vulnerability. A fix is available — see the affected versions and patch details below.

GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c

Published
Jul 7, 2026
Updated
Sep 10, 2026
Affected
32 versions
Patched
See advisory
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-58471.

EPSS Exploitation Probability

via FIRST.org ↗
0.4%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs31th percentile — riskier than 31% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for CVE-2026-58471, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate

Moderate: A heap buffer overflow in GNU Wget, affecting Red Hat Enterprise Linux and other products, can be triggered by a remote attacker. This flaw occurs when `wget` processes a specially crafted server-supplied filename that requires character set conversion, leading to memory corruption. Successful exploitation…

Workaround published by Red Hat
To mitigate this issue, always use the -O (or --output-document) flag in your scripts to explicitly define the local filename. This forces wget to ignore the server's provided filename, completely bypassing the vulnerable code path.
Source: Red Hat security advisory for CVE-2026-58471 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Enterprise Linux 10wget-0:1.24.5-8.el10_2RHSA-2026:62142
Red Hat Enterprise Linux 8wget-0:1.19.5-16.el8_10RHSA-2026:62144
Red Hat Enterprise Linux 9wget-0:1.21.1-11.el9_8RHSA-2026:62143
UbuntuMEDIUM

Frequently Asked Questions

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
O3 Security · Impact-Aware SCA

Is CVE-2026-58471 in your dependencies?

Find it across , including transitive dependencies.