Vulnerability Description
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead to memory corruption. This can cause the application to crash and potentially allow for further malicious activities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Wget2 | >= 2.1.0, < 2.2.1 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2025-69195Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2425770Issue TrackingThird Party Advisory
FAQ
What is CVE-2025-69195?
CVE-2025-69195 is a vulnerability with a CVSS score of 7.6 (HIGH). A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename re...
How severe is CVE-2025-69195?
CVE-2025-69195 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69195?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Wget2.