GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58471.json"
}{
"cpe": "cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.25.0"
}
]
}"2026-07-15T14:03:05Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-58471.json"
[
{
"digest": {
"line_hashes": [
"294500228288664263625566711264141674268",
"199220650042591654369529381888353120125",
"95353833620347814771463094521014642397",
"242719895248178841474821771296533257917",
"48869115540669839174357667352734493065",
"278072853899392985474035146633435263733",
"261827622472641176285802154208345937009",
"117736049488357435672958566244550401902",
"260366348520192133835145400447701741387",
"182083678579101949302146237586105708061",
"178166415751543498109291477949194743683",
"204343209596003018662545539021124742601",
"324778690218820308708773285349555998474",
"50988566751615329397715604544818724913",
"306820567038559673937729912774310426983",
"282215887192772135856808672275956114641",
"141963259781630858488931853108443860237",
"239498595861488396254100329307580822270",
"192625165309822972587069235614994581664"
],
"threshold": 0.9
},
"id": "CVE-2026-58471-691fc610",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://gitlab.com/gnuwget/wget@c2640fe5171c59f87c58dc9fcb195b2d18b010ee",
"target": {
"file": "src/url.c"
}
},
{
"digest": {
"function_hash": "65550410819091286333420077388895906521",
"length": 1649.0
},
"id": "CVE-2026-58471-b11efdd3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://gitlab.com/gnuwget/wget@c2640fe5171c59f87c58dc9fcb195b2d18b010ee",
"target": {
"function": "convert_fname",
"file": "src/url.c"
}
}
]