๐Ÿ” CVE Alert

CVE-2026-76014

LOW 3.3

BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.

CWE CWE-476 CWE-404
Vendor n/a
Product busybox
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for n/a busybox

Be the first to know when new low vulnerabilities affecting n/a busybox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / BusyBox
1.30.0 1.30.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/391923 vuldb.com: https://vuldb.com/vuln/391923/cti vuldb.com: https://vuldb.com/cve/CVE-2026-76014 vuldb.com: https://vuldb.com/submit/878212 github.com: https://github.com/mirror/busybox/issues/124 gist.github.com: https://gist.github.com/wyxstarry/5c199ec824928c5ae5816aaecbc6df03 github.com: https://github.com/mirror/busybox/commit/83a40bf7a93c8ac093d33ab452222dd5b9eb57ff

Credits

๐Ÿ” yuxin_wang (VulDB User)