JLSEC-2026-1159

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1159.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1159.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-1159
Upstream
  • EUVD-2026-42082
  • GHSA-5f52-px6m-c5hw
Published
2026-08-03T21:18:59.775Z
Modified
2026-08-03T21:44:01.276538556Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in...
Details

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

Database specific
{
    "sources": [
        {
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58470",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58470",
            "imported": "2026-08-03T20:01:18.272Z",
            "modified": "2026-07-09T16:01:18.490Z",
            "published": "2026-07-07T21:17:28.553Z",
            "database_specific": {
                "status": "Analyzed"
            },
            "id": "CVE-2026-58470"
        },
        {
            "modified": "2026-07-07T21:31:43Z",
            "imported": "2026-08-03T20:01:36.432Z",
            "url": "https://api.github.com/advisories/GHSA-5f52-px6m-c5hw",
            "html_url": "https://github.com/advisories/GHSA-5f52-px6m-c5hw",
            "published": "2026-07-07T21:31:36Z",
            "id": "GHSA-5f52-px6m-c5hw"
        },
        {
            "modified": "2026-07-14T22:03:11Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42082",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-42082",
            "imported": "2026-08-03T20:01:19.724Z",
            "published": "2026-07-07T19:45:53Z",
            "id": "EUVD-2026-42082"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / wget_jll

Package

Name
wget_jll
Purl
pkg:julia/wget_jll?uuid=25883557-5102-5516-a11b-f84f27e871d7

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1159.json"