openSUSE-SU-2026:20038-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20038-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20038-1
Upstream
CVE (2)
Related
Published
2026-01-14T13:23:53Z
Modified
2026-03-23T04:54:42Z
Summary
Security update for wget2
Details

This update for wget2 fixes the following issues:

Changes in wget2:

  • Update to release 2.2.1

    • Fix file overwrite issue with metalink [CVE-2025-69194 bsc#1255728]
    • Fix remote buffer overflow in get_local_filename_real() [CVE-2025-69195 bsc#1255729]
    • Fix a redirect/mirror regression from 400713ca
    • Use the local system timestamp when requested via --no-use-server-timestamps
    • Prevent file truncation with --no-clobber
    • Improve messages about why URLs are not being followed
    • Fix metalink with -O/--output-document
    • Fix sorting of metalink mirrors by priority
    • Add --show-progress to improve backwards compatibility to wget
    • Fix buffer overflow in wget_iri_clone() after wget_iri_set_scheme()
    • Allow 'no_' prefix in config options
    • Use libnghttp2 for HTTP/2 testing
    • Set exit status to 8 on 403 response code
    • Fix convert-links
    • Fix --server-response for HTTP/1.1
  • Update to release 2.2.0

    • Don't truncate file when -c and -O are combined
    • Don't log URI userinfo to logs
    • Fix downloading multiple files via HTTP/2
    • Support connecting with HTTP/1.0 proxies
    • Ignore 1xx HTTP responses for HTTP/1.1
    • Disable TCP Fast Open by default
    • Fix segfault when OCSP response is missing
    • Add libproxy support
References

Affected packages

openSUSE:Leap 16.0 / wget2

Package

Name
wget2
Purl
pkg:rpm/opensuse/wget2&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.1-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "libwget4":  "2.2.1-bp160.1.1",
            "wget2":  "2.2.1-bp160.1.1",
            "wget2-devel":  "2.2.1-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20038-1.json"