wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wget | Jul 30, 2024 | Apr 27, 2005 |
| Freebsd | — | Upgrade wget-develUpgrade wget+ipv6Upgrade wgetUpgrade wgetpro | Dec 10, 2025 | Dec 14, 2004 |
| Suse | — | Upgrade wget | Feb 17, 2015 | Apr 27, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub