VDB
GCVE-110-MAGEIA-2026-300
GCVE-110-MAGEIA-2026-300
Advisory Published
Updated wget packages fix security vulnerabilities:
-CVE-2026-58469 Wget incorrectly handled Metalink documents containing
a whitespace-only URL. A remote attacker could possibly use this issue
to cause a denial of service. This issue only affected Mageia 9 and
Mageia 10.
-CVE-2026-58470 : Wget incorrectly handled Content-Range header values,
leading to an integer overflow. A remote attacker could possibly use
this issue to cause download desynchronization.
-CVE-2026-58471 : Wget incorrectly handled character set conversion of
server-supplied filenames. A remote attacker could possibly use this
issue to cause a denial of service or possibly execute arbitrary code.
This issue affected Mageia9 and Mageia 10.
-CVE-2026-58472: It was discovered that Wget incorrectly handled HTML
attributes requiring entity encoding. A remote attacker could possibly
use this issue to cause a denial of service or possibly execute
arbitrary code.
-CVE-2026-15146: GNU Wget did not validate the IP address provided by an
FTP PASV response while operating in FTP passive mode. A malicious FTP
server, or an HTTP server that redirects to an FTP URL, could exploit
this behavior to redirect Wget's data connection to an arbitrary
IP address and port.
This allowed an attacker to forge server-side requests (SSRF) from the
machine running Wget, potentially accessing localhost services or
internal network resources.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | wget | 0 (affected), 1.25.0-2.2.mga10 (unaffected) | — |
| Mageia | wget | 0 (affected), 1.21.4-1.4.mga9 (unaffected) | — |
Browse GCVE Records
67,521 records in the GCVE database · Updated August 12, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.