CVE-2026-76014
BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue.
| CWE | CWE-476 CWE-404 |
| Vendor | n/a |
| Product | busybox |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a busybox
Be the first to know when new low vulnerabilities affecting n/a busybox are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / BusyBox
1.30.0 1.30.1
References
vuldb.com: https://vuldb.com/vuln/391923 vuldb.com: https://vuldb.com/vuln/391923/cti vuldb.com: https://vuldb.com/cve/CVE-2026-76014 vuldb.com: https://vuldb.com/submit/878212 github.com: https://github.com/mirror/busybox/issues/124 gist.github.com: https://gist.github.com/wyxstarry/5c199ec824928c5ae5816aaecbc6df03 github.com: https://github.com/mirror/busybox/commit/83a40bf7a93c8ac093d33ab452222dd5b9eb57ff
Credits
๐ yuxin_wang (VulDB User)