CVE-2024-38428
published 2024-06-16CVE-2024-38428: url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was…
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.67%
47.7th percentile
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wget | < wget 1.21.3-1+deb12u1 (bookworm) | wget 1.21.3-1+deb12u1 (bookworm) |
| gnu | wget | <= 1.24.5 | — |
| gnu | wget | >= 0 < 1.21-1+deb11u2 | 1.21-1+deb11u2 |
| gnu | wget | >= 0 < 1.21.3-1+deb12u1 | 1.21.3-1+deb12u1 |
| gnu | wget | >= 0 < 1.24.5-2 | 1.24.5-2 |
| gnu | wget | >= 0 < 1.24.5-2 | 1.24.5-2 |
| msrc | cbl2_wget_1.21.2-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_wget_1.21.2-4_on_cbl_mariner_2.0 | — | — |
| ubuntu | wget | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Wget vulnerabilities
vendor_ubuntu·2026-07-14·CVSS 9.1
CVE-2026-58470 [CRITICAL] Wget vulnerabilities
Title: Wget vulnerabilities
Summary: Several security issues were fixed in Wget.
It was discovered that Wget mishandled semicolons in the userinfo
subcomponent of a URL. A remote attacker could possibly use this issue
to trick a user into connecting to a different host than intended. This
issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428)
It was discovered that Wget incorrectly handled Metalink documents
containing a whitespace-only URL. A remote attacker could possibly use
this issue to cause a denial of service. This issue only affected Ubuntu
18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu
26.04 LTS. (CVE-2026-58469)
It was discovered that Wget incorrectly handled Content-Range header
values, leading to an integer overflow. A remote attacker could
pos
Ubuntu
Wget vulnerability
vendor_ubuntu·2024-06-27
CVE-2024-38428 Wget vulnerability
Title: Wget vulnerability
Summary: Wget could be made to connect to a different host than expected.
USN-6852-1 fixed a vulnerability in Wget. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Wget vulnerability
vendor_ubuntu·2024-06-26
CVE-2024-38428 Wget vulnerability
Title: Wget vulnerability
Summary: Wget could be made to connect to a different host than expected.
It was discovered that Wget incorrectly handled semicolons in the userinfo
subcomponent of a URI. A remote attacker could possibly trick a user into
connecting to a different host than expected.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent
vendor_msrc·2024-06-11·CVSS 9.1
CVE-2024-38428 [CRITICAL] CWE-436 url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to
Red Hat
wget: Misinterpretation of input may lead to improper behavior
vendor_redhat·2024-06-01·CVSS 9.1
CVE-2024-38428 [CRITICAL] CWE-115 wget: Misinterpretation of input may lead to improper behavior
wget: Misinterpretation of input may lead to improper behavior
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
A flaw was found in wget. Incorrect handling of semicolons in the userinfo subcomponent of a URI allows it to be misinterpreted as part of the host subcomponent, potentially exposing user credentials.
Statement: Only calls to Wget using semicolons in the userinfo subcomponent of a URI are vulnerable to this issue. However, this is allowed by the standard and is supported by other similar tools.
To exploit this issue, an attacker must convince a local user into running Wget
Debian
CVE-2024-38428: wget - url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcompon...
vendor_debian·2024·CVSS 9.1
CVE-2024-38428 [CRITICAL] CVE-2024-38428: wget - url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcompon...
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Scope: local
bookworm: resolved (fixed in 1.21.3-1+deb12u1)
bullseye: resolved (fixed in 1.21-1+deb11u2)
forky: resolved (fixed in 1.24.5-2)
sid: resolved (fixed in 1.24.5-2)
trixie: resolved (fixed in 1.24.5-2)
GHSA
GHSA-2j66-vp53-phjj: url
ghsa_unreviewed·2024-06-16
CVE-2024-38428 [CRITICAL] CWE-436 GHSA-2j66-vp53-phjj: url
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
OSV
CVE-2024-38428: url
osv·2024-06-16·CVSS 9.1
CVE-2024-38428 [CRITICAL] CVE-2024-38428: url
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242acehttps://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.htmlhttps://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242acehttps://lists.debian.org/debian-lts-announce/2025/04/msg00029.htmlhttps://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.htmlhttps://security.netapp.com/advisory/ntap-20241115-0005/
2024-06-16
Published