CRITICAL 9.1 Microsoft

CVE-2024-38428

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Microsoft Security Update 2024-Jun: url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Affected Products

References

Published: 2024-06-11 · Source: Microsoft · Feed updated: 2026-09-17
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-06-11 via Microsoft. Affected: cbl2 wget 1.21.2-3 on CBL Mariner 2.0, cbl2 wget 1.21.2-4 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2024-06-11 · 827 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-49844 PoCRedis Lua Use-After-Free may lead to remote code executionCRITICAL9.9
CVE-2024-41110 PoCMoby authz zero length regressionCRITICAL9.9
CVE-2024-24790Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netipCRITICAL9.8
CVE-2024-39331In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link CRITICAL9.8
CVE-2024-4577 PoCArgument Injection in PHP-CGICRITICAL9.8
CVE-2024-38541of: module: add buffer overflow check in of_modalias()CRITICAL9.8
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.