Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Mageia wget Important Denial of Service Threats and Updates 2026-0300

mageia
Calendar Grey July 25, 2026
Scroller Mageia
Critical security updates for Mageia's wget resolve multiple vulnerabilities, including denial of service and potential remote code execution risks.
Mageia released updated wget packages addressing multiple security vulnerabilities, including denial of service and potential arbitrary code execution, affecting Mageia 9 and 10

Summary

Description: Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not v...

References

- https://bugs.mageia.org/show_bug.cgi?id=35974

- https://ubuntu.com/security/notices/USN-8543-1

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/MLFETWDGXIX52KIZRAM7CSI5NHATXLCF/

- https://www.cve.org/CVERecord?id=CVE-2026-58469

- https://www.cve.org/CVERecord?id=CVE-2026-58470

- https://www.cve.org/CVERecord?id=CVE-2026-58471

- https://www.cve.org/CVERecord?id=CVE-2026-58472

- https://www.cve.org/CVERecord?id=CVE-2026-15146

Resolution

SRPMS

- 10/core/wget-1.25.0-2.2.mga10

- 9/core/wget-1.21.4-1.4.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0300.html
Type: security
CVE: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472, CVE-2026-15146

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.