Wget Vulnerabilities in Ubuntu Lead to Denial of Service Risks

Wget Vulnerabilities in Ubuntu Lead to Denial of Service Risks

First seen 21 Aug 2026, 12:48 UTC UbuntuLinuxsecurity 93% similarity 57.8

Article Content

Browse articles
ThreatCluster

A regression introduced by USN-8543-1 in Wget has been addressed in USN-8543-2. The update for CVE-2026-58472 was incomplete, potentially allowing remote attackers to exploit vulnerabilities. Affected systems include Ubuntu 14.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS. Specific vulnerabilities include mishandling of semicolons in URLs (CVE-2024-38428) and whitespace-only URLs leading to denial of service (CVE-2026-58469). Additional issues include integer overflow (CVE-2026-58470) and character set conversion problems (CVE-2026-58471). Users are advised to update their systems to mitigate these risks. The vulnerabilities could allow attackers to trick users or cause service disruptions.

Key Points: • USN-8543-1 introduced a regression in Wget affecting multiple Ubuntu versions. • Critical vulnerabilities include denial of service risks and potential remote code execution. • Users are urged to update to the latest package versions to secure their systems.

ThreatCluster AI How this analysis works

Timeline

2024-06-16
CVE-2024-38428 published
Wget mishandled semicolons in URLs, allowing potential host redirection attacks.
Ubuntu
2026-07-07
CVE-2026-58469 published
Wget incorrectly handled whitespace-only URLs, leading to denial of service vulnerabilities.
Ubuntu
2026-07-07
CVE-2026-58470 published
Integer overflow in Wget could cause download desynchronization, affecting service integrity.
Ubuntu
2026-07-07
CVE-2026-58471 published
Wget's mishandling of character set conversions could lead to denial of service or code execution.
Ubuntu
2026-07-07
CVE-2026-58472 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
USN-8543-2 released
An update was issued to fix the regression introduced by USN-8543-1 in Wget.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story