logo

Critical Wget2 Flaws Expose Users to Arbitrary File Overwrites and Memory Crashes

ID: e9e5d969-9463-5b1e-9041-13053fbcc1c9

STIX ID: report--e9e5d969-9463-5b1e-9041-13053fbcc1c9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-02

Date Updated: 2026-04-22

Author: Ddos

...
...

Two serious security flaws were disclosed in GNU Wget2: a Metalink v3/v4 path traversal (CVE-2025-69194) that can trust attacker-supplied <file name> values and overwrite arbitrary files (potentially enabling remote code execution), and a stack-based buffer overflow (CVE-2025-69195) in filename-sanitization logic that can cause memory corruption or crashes; both are remotely exploitable without authentication and only require a user to download or follow a malicious link, so users should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.