CVE-2026-58471 — wget
CVE-2026-58471 is a remote code execution vulnerability. A fix is available — see the affected versions and patch details below.
GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-58471.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Fix
Upgrade the affected component to the fixed release for CVE-2026-58471, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.
Workarounds
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Moderate: A heap buffer overflow in GNU Wget, affecting Red Hat Enterprise Linux and other products, can be triggered by a remote attacker. This flaw occurs when `wget` processes a specially crafted server-supplied filename that requires character set conversion, leading to memory corruption. Successful exploitation…
To mitigate this issue, always use the -O (or --output-document) flag in your scripts to explicitly define the local filename. This forces wget to ignore the server's provided filename, completely bypassing the vulnerable code path.Source: Red Hat security advisory for CVE-2026-58471 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 10 | wget-0:1.24.5-8.el10_2 | RHSA-2026:62142 |
| Red Hat Enterprise Linux 8 | wget-0:1.19.5-16.el8_10 | RHSA-2026:62144 |
| Red Hat Enterprise Linux 9 | wget-0:1.21.1-11.el9_8 | RHSA-2026:62143 |
Frequently Asked Questions
Is CVE-2026-58471 in your dependencies?
Find it across , including transitive dependencies.