Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Description: Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not v...
- https://bugs.mageia.org/show_bug.cgi?id=35974
- https://ubuntu.com/security/notices/USN-8543-1
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/MLFETWDGXIX52KIZRAM7CSI5NHATXLCF/
- https://www.cve.org/CVERecord?id=CVE-2026-58469
- https://www.cve.org/CVERecord?id=CVE-2026-58470
- https://www.cve.org/CVERecord?id=CVE-2026-58471
- https://www.cve.org/CVERecord?id=CVE-2026-58472
- https://www.cve.org/CVERecord?id=CVE-2026-15146
- 10/core/wget-1.25.0-2.2.mga10
- 9/core/wget-1.21.4-1.4.mga9
Publication date:25 Jul 2026
Get the latest Linux and open source security news straight to your inbox.