Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16599

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

A flaw was found in wget's FTP OPIE/S-KEY authentication functionality. A malicious FTP server or a network attacker can send a specially crafted OPIE challenge. This challenge contains a sequence number that, when processed by wget, can lead to an excessive number of cryptographic computations. This prolonged computation can cause wget to become unresponsive, resulting in a denial of service.

Отчет

All versions of wget as shipped with Red Hat Enterprise Linux, Red Hat In-Vehicle Operating System, and Fedora are affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10wgetFix deferred
Red Hat Enterprise Linux 6wgetFix deferred
Red Hat Enterprise Linux 7wgetFix deferred
Red Hat Enterprise Linux 8wgetFix deferred
Red Hat Enterprise Linux 9wgetFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2523509wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge

EPSS

Процентиль: 32%
0.0038
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
28 дней назад

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

nvd
28 дней назад

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

debian
28 дней назад

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...

suse-cvrf
14 дней назад

Security update for wget

suse-cvrf
15 дней назад

Security update for wget

EPSS

Процентиль: 32%
0.0038
Низкий

6.5 Medium

CVSS3