Skip to content
Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response

Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response

First seen 21 Jul 2026, 09:36 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 06:39 UTC
  • Wget's failure to validate FTP PASV response IP addresses poses a serious security risk.
  • Remote attackers can exploit this vulnerability for server-side request forgery.
  • Affected Ubuntu versions require immediate updates to mitigate the risk.

A vulnerability in Wget was identified, where it fails to validate IP addresses in FTP PASV responses. This flaw allows remote attackers controlling a malicious FTP server or an HTTP server redirecting to an FTP URL to redirect Wget's data connection to arbitrary addresses. This could lead to server-side request forgery, potentially exposing localhost services or internal network resources. The affected versions include multiple Ubuntu releases, with specific package versions outlined for updates. Users are advised to perform a standard system update to mitigate the issue. The vulnerability is documented as USN-8572-1.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 63d ago How this analysis works

Timeline

2026-07-20
Wget vulnerability disclosed
Ubuntu published USN-8572-1 detailing a vulnerability in Wget affecting multiple versions.
Ubuntu
2026-07-20
Linuxsecurity reports on Wget vulnerability
Linuxsecurity published an advisory on the Wget vulnerability, emphasizing the potential for server-side request forgery.
Linuxsecurity

More articles in this cluster (2)