CVE-2026-16599
published 2026-08-25CVE-2026-16599: GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line…
PriorityP431medium5.1CVSS 4.0
AVNACLATNPRNUIAVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.38%
31.0th percentile
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | wget | <= 1.25.0 | — |
| gnu | wget | — | — |
CVSS provenance
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality.
ghsa_unreviewed·2026-08-25
CVE-2026-16599 [MEDIUM] CWE-606 GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality.
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
Red Hat
wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
vendor_redhat·2026-08-25·CVSS 5.1
CVE-2026-16599 [MEDIUM] CWE-835 wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
A flaw was found in wget's FTP
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-16599 wget1: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge [fedora-all]
bugzilla·2026-08-26·CVSS 5.1
CVE-2026-16599 [MEDIUM] CVE-2026-16599 wget1: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge [fedora-all]
CVE-2026-16599 wget1: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billio
Bugzilla
CVE-2026-16599 wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
bugzilla·2026-08-25·CVSS 5.1
CVE-2026-16599 [MEDIUM] CVE-2026-16599 wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
CVE-2026-16599 wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
2026-08-25
Published