Description:
The wget packages provide the GNU Wget file retrieval utility for HTTP, HTTPS, and FTP protocols.
Security Fix(es):
* wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption (CVE-2026-58471)
* wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute (CVE-2026-58472)
Bug Fix(es) and Enhancement(s):
* wget async unsafe code in signal handler context [almalinux-9.8.z] (JIRA:AlmaLinux-220497)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
wget-1.21.1-11.el9_8.aarch64.rpm |
f8dd1d4e7a236f7f6cb4bd6f6b53d85f6db52c88243c277ab496265c355b90fc |
| ppc64le |
wget-1.21.1-11.el9_8.ppc64le.rpm |
2722834cdfbc992a1a49ff110661963f450b0453db178c32e4fdec632733a95e |
| s390x |
wget-1.21.1-11.el9_8.s390x.rpm |
c8acb94be13182b86886a5a826c8090e47c3eb620cd0633b39fca6c38233c624 |
| x86_64 |
wget-1.21.1-11.el9_8.x86_64.rpm |
832eca3a83c8903f6d656adc6509da0cfec899e27b6d35489635fea7dabb80fb |