{"id":"CVE-2026-58472","summary":"GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding","details":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.","modified":"2026-07-24T17:23:08.879009925Z","published":"2026-07-07T19:50:53.967Z","related":["SUSE-SU-2026:3148-1","SUSE-SU-2026:3205-1","SUSE-SU-2026:3206-1","openSUSE-SU-2026:11252-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58472.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58472.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58472"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"},{"type":"FIX","url":"https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"},{"type":"PACKAGE","url":"https://gitlab.com/gnuwget/wget"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gnuwget/wget","events":[{"introduced":"0"},{"fixed":"dd692d9cea5335b181d877ae917fe6e75587a812"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.25.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.25.0","v1.24.5","v1.21.4","v1.21.3","v1.21.2","v1.21.1","v1.21","v1.20.3","v1.20.2","v1.20.1","v1.20","v1.19.5","v1.19.4","v1.19.3","v1.19.2","v1.19.1","v1.19","v1.18","v1.17.1","v1.17","v1.16.3","v1.16.2","v1.16.1","v1.16","v1.15","v1.14","v1.13.4","v1.13.3","v1.13.2","v1.13.1","v1.13","v1.12"],"database_specific":{"vanir_signatures_modified":"2026-07-15T14:03:05Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/gnuwget/wget@dd692d9cea5335b181d877ae917fe6e75587a812","target":{"file":"src/convert.c"},"deprecated":false,"digest":{"line_hashes":["199182357809529623688222713766080133238","135212105797410110083668158492137451927","278823367891411785948700602687338115408","222588612859478639981791596303316826076","255870176975768309625979113284697718472","201929387705719422185455098915189410111","38570025885954457775063338027420572944","179250787530478780473293467226234222876","111561696374708401675658642401381706952","324247327998281272902983770223258545732","215847536091761988034876366428378873964","257548772929790741928583443619198148197","298513403085199463986501409209355700696","137207773316618270851453856926200960659","323765802171222299116629004769293798484","22625333874938592454494960384024649822","51167852704852622884562213243626484377","305816076677486035627311906503048594941","275549255149626703415380327012067846029","80695035497579884336848661410450230691"],"threshold":0.9},"id":"CVE-2026-58472-80d2d4fc"},{"target":{"file":"src/convert.c","function":"html_quote_string"},"deprecated":false,"digest":{"length":945,"function_hash":"266493759714671336150758635811033650311"},"id":"CVE-2026-58472-c3a1b5d2","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/gnuwget/wget@dd692d9cea5335b181d877ae917fe6e75587a812"}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58472.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}]}