USN-8543-2: Wget regression

Publication date

20 August 2026

Overview

USN-8543-1 introduced a regression in Wget.


Packages

  • wget - retrieves files from the web

Details

USN-8543-1 fixed vulnerabilities in Wget. The update for CVE-2026-58472
was incomplete and could introduce a regression. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)

It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-58469)

It...

USN-8543-1 fixed vulnerabilities in Wget. The update for CVE-2026-58472
was incomplete and could introduce a regression. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)

It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-58469)

It was discovered that Wget incorrectly handled Content-Range header
values, leading to an integer overflow. A remote attacker could
possibly use this issue to cause download desynchronization.
(CVE-2026-58470)

It was discovered that Wget incorrectly handled character set
conversion of server-supplied filenames. A remote attacker could
possibly use this issue to cause a denial of service or possibly execute
arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58471)

It was discovered that Wget incorrectly handled HTML attributes
requiring entity encoding. A remote attacker could possibly use this
issue to cause a denial of service or possibly execute arbitrary code.
(CVE-2026-58472)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute wget –  1.25.0-2ubuntu4.4
24.04 LTS noble wget –  1.21.4-1ubuntu4.5
22.04 LTS jammy wget –  1.21.2-2ubuntu1.5
20.04 LTS focal wget –  1.20.3-1ubuntu2.1+esm4  
18.04 LTS bionic wget –  1.19.4-1ubuntu2.2+esm5  
16.04 LTS xenial wget –  1.17.1-1ubuntu1.5+esm5  
14.04 LTS trusty wget –  1.15-1ubuntu1.14.04.5+esm4  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›