> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> USN-8572-1: Wget vulnerability

[SOURCE] Ubuntu Security Notices [DATE: 20/07/2026 19:12] [LANGUAGE: EN]
It was discovered that Wget did not properly validate the IP address provided in an FTP PASV response when operating in FTP passive mode. A remote attacker controlling a malicious FTP server, or an HTTP server that redirects to an FTP URL, could possibly use this issue to redirect Wget's data connection to an arbitrary address and perform server-side request forgery, potentially accessing localhost services or internal network resources.
[messages.read_original_source] →