Explore top 10 tips to secure your open-source projects now. Read More
×Wget could be made to connect to unintended network resources.. ========================================================================== Ubuntu Security Notice USN-8572-1 July 20, 2026 wget vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Wget could be made to connect to unintended network resources. Software Description: - wget: retrieves files from the web Details: It was discovered that Wget did not properly validate the IP address provided in an FTP PASV response when operating in FTP passive mode. A remote attacker controlling a malicious FTP server, or an HTTP server that redirects to an FTP URL, could possibly use this issue to redirect Wget's data connection to an arbitrary address and perform server-side request forgery, potentially accessing localhost services or internal network resources. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS wget 1.25.0-2ubuntu4.3 Ubuntu 24.04 LTS wget 1.21.4-1ubuntu4.4 Ubuntu 22.04 LTS wget 1.21.2-2ubuntu1.4 Ubuntu 20.04 LTS wget 1.20.3-1ubuntu2.1+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS wget 1.19.4-1ubuntu2.2+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS wget 1.17.1-1ubuntu1.5+esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS wget 1.15-1ubuntu1.14.04.5+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8572-1 CVE-2026-15146 Package Information: https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.3 https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.4 https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.4 . Address a Wget issue in Ubuntu which could allow unintended network connections, exposing internal resources.. Ubuntu Wget security update, network vulnerability fix, server-side request forgery mitigation. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # wget-1.25.0-4.1 on GA media Announcement ID: openSUSE-SU-2026:11303-1 Rating: moderate Cross-References: * CVE-2026-15146 CVSS scores: * CVE-2026-15146 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-15146 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the wget-1.25.0-4.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * wget 1.25.0-4.1 * wget-lang 1.25.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15146.html . An update is available for openSUSE Tumbleweed addressing a moderate issue in wget with CVE-2026-15146 and CVSS scores.. openSUSE updates,wget vulnerabilities,security advisory Tumbleweed. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Wget.. ========================================================================== Ubuntu Security Notice USN-8543-1 July 14, 2026 wget vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Wget. Software Description: - wget: retrieves files from the web Details: It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intended. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428) It was discovered that Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58469) It was discovered that Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. (CVE-2026-58470) It was discovered that Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471) It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58472) Update instructions: The problem can be corrected by updating your system tothe following package versions: Ubuntu 26.04 LTS wget 1.25.0-2ubuntu4.2 Ubuntu 24.04 LTS wget 1.21.4-1ubuntu4.3 Ubuntu 22.04 LTS wget 1.21.2-2ubuntu1.3 Ubuntu 20.04 LTS wget 1.20.3-1ubuntu2.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS wget 1.19.4-1ubuntu2.2+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS wget 1.17.1-1ubuntu1.5+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS wget 1.15-1ubuntu1.14.04.5+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8543-1 CVE-2024-38428, CVE-2026-58469, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472 Package Information: https://launchpad.net/ubuntu/+source/wget/1.25.0-2ubuntu4.2 https://launchpad.net/ubuntu/+source/wget/1.21.4-1ubuntu4.3 https://launchpad.net/ubuntu/+source/wget/1.21.2-2ubuntu1.3 . Several security issues were fixed in Wget affecting multiple Ubuntu versions, including critical flaws that may allow remote code execution.. Wget Updates, Ubuntu Security, Remote Attacks, Code Execution, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
* bsc#1233773 Cross-References: * CVE-2024-10524 . # Security update for wget Announcement ID: SUSE-SU-2025:01921-1 Release Date: 2025-06-12T06:29:35Z Rating: moderate References: * bsc#1233773 Cross-References: * CVE-2024-10524 CVSS scores: * CVE-2024-10524 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-10524 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2024-10524 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2024-10524: Dropped support for shorthand URLs that enabled SSRF attacks (bsc#1233773). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1921=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * wget-1.14-21.25.1 * wget-debuginfo-1.14-21.25.1 * wget-debugsource-1.14-21.25.1 ## References: * https://www.suse.com/security/cve/CVE-2024-10524.html * https://bugzilla.suse.com/show_bug.cgi?id=1233773 . A security update for wget on SUSE has been issued to fix a moderate severity SSRF vulnerability. Administrators should update to reduce security risks. SUSE, wget, SSRF, patch, security advisory. . LinuxSecurity.com Team
* bsc#1226419 Cross-References: * CVE-2024-38428 . # Security update for wget Announcement ID: SUSE-SU-2025:20010-1 Release Date: 2025-02-03T08:47:43Z Rating: moderate References: * bsc#1226419 Cross-References: * CVE-2024-38428 CVSS scores: * CVE-2024-38428 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-38428 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-38428 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2024-38428: Fix mishandled semicolons in the userinfo subcomponent of a URI. (bsc#1226419) * Update to GNU wget 1.24.5: * Fix how subdomain matches are checked for HSTS. * Wget will now also parse the srcset attribute in HTML tags * Support reading fetchmail style "user" and "passwd" fields from netrc * In some cases, prevent the confusing "Cannot write to... (success)" error messages * Support extremely fast download speeds (TB/s) * Ensure that CSS URLs are corectly quoted * libproxy support is now upstream- drop wget-libproxy.patch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-11=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * wget-1.24.5-1.1 * wget-debugsource-1.24.5-1.1 * wget-debuginfo-1.24.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38428.html * https://bugzilla.suse.com/show_bug.cgi?id=1226419 . SUSE releases a new version of wget to resolve security vulnerability CVE-2024-38429, which impacts Linux Micro 6.0 and carries a moderate severity classification.. SUSE wget update, security patch, Linux Micro6.0. . LinuxSecurity.com Team
* bsc#1226419 Cross-References: * CVE-2024-38428 . # Security update for wget Announcement ID: SUSE-SU-2025:20010-1 Release Date: 2025-02-03T08:47:43Z Rating: moderate References: * bsc#1226419 Cross-References: * CVE-2024-38428 CVSS scores: * CVE-2024-38428 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-38428 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-38428 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2024-38428: Fix mishandled semicolons in the userinfo subcomponent of a URI. (bsc#1226419) * Update to GNU wget 1.24.5: * Fix how subdomain matches are checked for HSTS. * Wget will now also parse the srcset attribute in HTML tags * Support reading fetchmail style "user" and "passwd" fields from netrc * In some cases, prevent the confusing "Cannot write to... (success)" error messages * Support extremely fast download speeds (TB/s) * Ensure that CSS URLs are corectly quoted * libproxy support is now upstream- drop wget-libproxy.patch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-11=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * wget-debuginfo-1.24.5-1.1 * wget-1.24.5-1.1 * wget-debugsource-1.24.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38428.html * https://bugzilla.suse.com/show_bug.cgi?id=1226419 . This notice outlines a significant patch for curl in openSUSE, resolving CVE-2024-54761 along with additional enhancements.. SUSE Security,Wget Update,CVE-2024-38428,SUSE Linux Micro 6.0,security fixes. .LinuxSecurity.com Team
* bsc#1233773 Cross-References: * CVE-2024-10524 . # Security update for wget Announcement ID: SUSE-SU-2025:20097-1 Release Date: 2025-02-03T09:14:08Z Rating: moderate References: * bsc#1233773 Cross-References: * CVE-2024-10524 CVSS scores: * CVE-2024-10524 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-10524 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2024-10524 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2024-10524: Drop support for shorthand URLs (bsc#1233773). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-128=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * wget-debuginfo-1.24.5-2.1 * wget-1.24.5-2.1 * wget-debugsource-1.24.5-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-10524.html * https://bugzilla.suse.com/show_bug.cgi?id=1233773 . Important patch released for SUSE Linux Micro tackling security flaw in wget, CVE-2024-10524, aimed at enhancing overall security measures.. SUSE Linux Micro,wget security update,CVE-2024-10524,security patch,moderate severity. . LinuxSecurity.com Team
* bsc#1233773 Cross-References: * CVE-2024-10524 . # Security update for wget Announcement ID: SUSE-SU-2025:20097-1 Release Date: 2025-02-03T09:14:08Z Rating: moderate References: * bsc#1233773 Cross-References: * CVE-2024-10524 CVSS scores: * CVE-2024-10524 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-10524 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2024-10524 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issues: * CVE-2024-10524: Drop support for shorthand URLs (bsc#1233773). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-128=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * wget-debuginfo-1.24.5-2.1 * wget-1.24.5-2.1 * wget-debugsource-1.24.5-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-10524.html * https://bugzilla.suse.com/show_bug.cgi?id=1233773 . Urgent safety enhancement for curl resolves CVE-2024-10525 on SUSE Micro 6.0. Implement update without delay.. SUSE Linux Micro,wget update,CVE-2024-10524,security advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.