CVE-2025-69195: Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls

Published Dec 29, 2025
·
Updated

A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead to memory corruption. This can cause the application to crash and potentially allow for further malicious activities.

Other sources

Stack-based buffer overflow vulnerability in the filename sanitization logic of GNU Wget2. The flaw occurs when wget2 processes attacker-controlled URL paths while filename restriction options such as --restrict-file-names=windows, unix, or ascii are enabled. During sanitization, the application writes beyond a fixed 1024-byte stack buffer due to missing bounds checks. A specially crafted URL path or HTTP redirect can trigger memory corruption, resulting in a crash or potentially enabling further exploitation. The issue can be triggered remotely with no authentication, requiring only user interaction to invoke wget2.

Red Hat

Affected Software

2 affected components
GNU Wget2
GNU Wget2>=2.1.0<2.2.1

Event History

Dec 29, 2025
Data Sourced
via Red Hat·02:06 PM
DescriptionSeverityAffected Software
Jan 9, 2026
CVE Published
via MITRE·07:57 AM
Data Sourced
via MITRE·07:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-69195?

CVE-2025-69195 is classified as a critical vulnerability due to its potential for exploitation through a stack-based buffer overflow.

2

How do I fix CVE-2025-69195?

To fix CVE-2025-69195, update GNU Wget2 to the latest version where the vulnerability has been patched.

3

What are the potential impacts of CVE-2025-69195?

The potential impacts of CVE-2025-69195 include remote code execution or a denial of service due to the buffer overflow.

4

Who is affected by CVE-2025-69195?

CVE-2025-69195 affects users of GNU Wget2, particularly those using filename restriction options.

5

Can CVE-2025-69195 be exploited remotely?

Yes, CVE-2025-69195 can be exploited remotely by attackers through specially crafted URL paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203