Linuxsecurity Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response
Article Content
Browse articles
- •Wget's failure to validate FTP PASV response IP addresses poses a serious security risk.
- •Remote attackers can exploit this vulnerability for server-side request forgery.
- •Affected Ubuntu versions require immediate updates to mitigate the risk.
A vulnerability in Wget was identified, where it fails to validate IP addresses in FTP PASV responses. This flaw allows remote attackers controlling a malicious FTP server or an HTTP server redirecting to an FTP URL to redirect Wget's data connection to arbitrary addresses. This could lead to server-side request forgery, potentially exposing localhost services or internal network resources. The affected versions include multiple Ubuntu releases, with specific package versions outlined for updates. Users are advised to perform a standard system update to mitigate the issue. The vulnerability is documented as USN-8572-1.
Ask AI about this cluster
Answers cite the sources they use
Updated 63d ago How this analysis works
Timeline
2026-07-20
Wget vulnerability disclosed
Ubuntu published USN-8572-1 detailing a vulnerability in Wget affecting multiple versions.
Ubuntu2026-07-20
Linuxsecurity reports on Wget vulnerability
Linuxsecurity published an advisory on the Wget vulnerability, emphasizing the potential for server-side request forgery.
LinuxsecurityMore articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…