boks Index
Docs Releases

wget

1 tool · 1 release line

Non-interactive network downloader. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing wget from wget@latest → 1.25.0 stable

Findings

M10

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-13757 ↗ M 6.2 p11-kit A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing…
CVE-2026-18938 ↗ M 6.2 p11-kit A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.
CVE-2021-31879 ↗ M 6.1 wget GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of wget, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/wget:1.25.0
digest
platforms
size 9 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

wget

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.wgetrc

env passed through

4 forwarded

ftp_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

1 set

SYSTEM_WGETRC

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

10 findings across this project at latest. Counted once per advisory across every image the project builds.