{"id":"CVE-2025-69195","summary":"Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls","details":"A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead to memory corruption. This can cause the application to crash and potentially allow for further malicious activities.","modified":"2026-08-12T03:51:21.906245554Z","published":"2026-01-09T07:57:17.240Z","related":["openSUSE-SU-2026:10015-1","openSUSE-SU-2026:20038-1"],"database_specific":{"cna_assigner":"fedora","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69195.json"},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-69195"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69195.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69195"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2425770"},{"type":"PACKAGE","url":"https://gitlab.com/gnuwget/wget2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gnuwget/wget2","events":[{"introduced":"657e3d22c488a2d1f173e208e253995e15f8b6db"},{"last_affected":"f2071aaaf6f947fd03d243c6b619302d31d497f1"}],"database_specific":{"extracted_events":[{"introduced":"2.1.0"},{"last_affected":"2.2.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.2.0","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69195.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"}]}