🛡️ MGASA-2026-0300 — wget

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Updated wget packages fix security vulnerabilities

Updated wget packages fix security vulnerabilities:

-CVE-2026-58469 Wget incorrectly handled Metalink documents containing

a whitespace-only URL. A remote attacker could possibly use this issue

to cause a denial of service. This issue only affected Mageia 9 and

Mageia 10.

-CVE-2026-58470 : Wget incorrectly handled Content-Range header values,

leading to an integer overflow. A remote attacker could possibly use

this issue to cause download desynchronization.

-CVE-2026-58471 : Wget incorrectly handled character set conversion of

server-supplied filenames. A remote attacker could possibly use this

issue to cause a denial of service or possibly execute arbitrary code.

This issue affected Mageia9 and Mageia 10.

-CVE-2026-58472: It was discovered that Wget incorrectly handled HTML

attributes requiring entity encoding. A remote attacker could possibly

use this issue to cause a denial of service or possibly execute

arbitrary code.

-CVE-2026-15146: GNU Wget did not validate the IP address provided by an

FTP PASV response while operating in FTP passive mode. A malicious FTP

server, or an HTTP server that redirects to an FTP URL, could exploit

this behavior to redirect Wget's data connection to an arbitrary

IP address and port.

This allowed an attacker to forge server-side requests (SSRF) from the

machine running Wget, potentially accessing localhost services or

internal network resources.

Affected software

MGASA-2026-0300 is recorded against 1 package.

  • wget (fixed in 1.21.4-1.4.mga9)

Timeline and source

Published on 25 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
ubuntu.com (Advisory)
lists.opensuse.org (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-25
Updated 2026-08-12
Modified 2026-07-25
Fix URL N/A

Affected Packages

Software From version Fixed in
wget 1.21.4-1.4.mga9

Similar Threats

Free Vulnerability Check

Is your site affected by MGASA-2026-0300?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2026-0300 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.