Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response

Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response

First seen 21 Jul 2026, 09:36 UTC UbuntuLinuxsecurity 86% similarity 57.9

Article Content

Browse articles
ThreatCluster

A vulnerability in Wget was identified, where it fails to validate IP addresses in FTP PASV responses. This flaw allows remote attackers controlling a malicious FTP server or an HTTP server redirecting to an FTP URL to redirect Wget's data connection to arbitrary addresses. This could lead to server-side request forgery, potentially exposing localhost services or internal network resources. The affected versions include multiple Ubuntu releases, with specific package versions outlined for updates. Users are advised to perform a standard system update to mitigate the issue. The vulnerability is documented as USN-8572-1.

Key Points: • Wget's failure to validate FTP PASV response IP addresses poses a serious security risk. • Remote attackers can exploit this vulnerability for server-side request forgery. • Affected Ubuntu versions require immediate updates to mitigate the risk.

ThreatCluster AI

Timeline

2026-07-20
Wget vulnerability disclosed
Ubuntu published USN-8572-1 detailing a vulnerability in Wget affecting multiple versions.
Ubuntu
2026-07-20
Linuxsecurity reports on Wget vulnerability
Linuxsecurity published an advisory on the Wget vulnerability, emphasizing the potential for server-side request forgery.
Linuxsecurity

Community

Browse all →