CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-38428

mediumcovered by 2 sourcesfirst seen 2026-07-14
It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intended. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428) It was discovered that Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58469) It was discovered that Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. (CVE-2026-58470) It was discovered that Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471) It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58472)

CSIRTS triage

vendor: GNUproduct: WgetDenial of serviceOtheraffected: Ubuntu 14.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, 26.04 LTS
What
Wget has multiple vulnerabilities that could lead to denial of service and other issues.
Who is affected
Users of Wget on the specified Ubuntu versions are affected by these vulnerabilities.
Urgency
Remediation is urgent for affected versions due to potential denial of service.
Action
Update Wget to the latest version available for your Ubuntu distribution.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2024-38428

Get an email if CVE-2024-38428 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2024-38428

CVE.org record

Embed the live status

CVE-2024-38428 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2024-38428 status](https://www.csirts.com/badge/CVE-2024-38428)](https://www.csirts.com/cve/CVE-2024-38428)