#1145868 wget: CVE-2026-16599

#1145868#5
Date:
2026-08-27 12:36:01 UTC
From:
To:
Hi,

The following vulnerability was published for wget.

CVE-2026-16599[0]:
| GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY
| authentication functionality. The server-supplied sequence number
| from the FTP challenge line is used as an iteration count for an MD5
| key-derivation loop without any upper bound validation. A malicious
| FTP server or a network attacker positioned to intercept FTP traffic
| can send a crafted OPIE challenge with a sequence number near
| INT_MAX, causing wget to perform up to approximately 2.1 billion MD5
| computations and suspend for some time. The --timeout option does
| not mitigate this because it applies only to network I/O, not CPU
| computation.   This issue was fixed in commit
| e9697d98e7249b0f68a6be040a4f3dcc5bc101fa


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16599
https://www.cve.org/CVERecord?id=CVE-2026-16599
[1] https://cert.pl/en/posts/2026/08/CVE-2026-16599/
[2] https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore