Skip to main content

Vendor/product archive

gnu / wget2 CVEs

Beta · best-effort

3 CVEs tagged to gnu / wget20 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-1858

Published Apr 29, 2026

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued fo…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-69195

Published Jan 9, 2026

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particul…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-69194

Published Jan 9, 2026

A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1