Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 485
Alerts This Week
Warning Icon 1 485

Fedora 44 Wget1 Significant Resolution for Various CVEs 2026-1b91a2f126

fedora
Calendar Grey July 20, 2026
Scroller Fedora
This advisory addresses critical fixes for multiple CVEs affecting the wget1 application in Fedora 44, enhancing system security.
Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472

Summary

GNU Wget is a file retrieval utility which can use either the HTTP or

FTP protocols. Wget features include the ability to work in the

background while you are logged out, recursive retrieval of

directories, file name wildcard matching, remote file timestamp

storage and comparison, use of Rest with FTP servers and Range with

HTTP servers to retrieve files over slow or unstable connections,

support for Proxy servers, and configurability.

Update Information:

Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472

Change Log

* Thu Jul 16 2026 Michal Ruprich - 1.25.0-4 - Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472 * Sat Jan 17 2026 Fedora Release Engineering - 1.25.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2499188 - CVE-2026-15146 wget1: Wget: Server-Side Request Forgery via FTP PASV response IP address validation bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499188 [ 2 ] Bug #2499583 - CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499583 [ 3 ] Bug #2499957 - CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499957 [ 4 ] Bug #2499971 - CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499971

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1b91a2f126' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: wget1
Product: Fedora 44
Version: 1.25.0
Release: 4.fc44
Summary: A utility for retrieving files using the HTTP or FTP protocols

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.