GNU Wget 2.3
Package
GNU Wget 2.3 converts links inside CSS when mirroring, follows lazy-loaded image attributes, keeps -i batch downloads going after errors, and hardens cookie, recursion, and path traversal handling.
Download TAR.GZ Project website ↗Download Mirrors
GNU Wget 2.3 was released on September 21, 2026. This is Wget2, the rewrite that some distributions install as wget and others ship alongside the classic Wget 1.x as wget2. We covered it in the news.
New features
--convert-linksnow rewrites links inside CSS, so mirrored sites work offline- Follows
iframe srcdocand lazy-loadingdata-src/data-srcsetattributes --progress=dotfor plain logs--spider -Sprints server headers without downloading-ibatch downloads continue after an error- Correct
Content-Length: 0on empty POST, PUT, and PATCH requests - Overly long filenames are truncated, and exit codes are correct after failed retries
Security fixes
- Integer overflow in cookie parsing; secure cookies are only accepted over HTTPS
- Stack overflow prevented in recursive local parsing; XML recursion capped at 1024 levels
- Stronger path traversal checks on
Content-Dispositionfilenames - Stricter TLS certificate validation. GnuTLS 3.6.5 or newer is now required
Using it
wget2 --version | head -1
wget2 -i urls.txt # batch download
wget2 --spider -S https://example.com/ # headers only
wget2 -m -k -p https://example.com/docs/ # mirror a site for offline use
Wget2 downloads in parallel by default, which makes large batches much faster, and improved Wget 1.x compatibility in this release helps existing scripts. Our curl and wget explainer covers which tool to reach for.
Verify Your Download
Every tarball on ftp.gnu.org has a matching .sig file. Verify it with the maintainer’s key from the GNU keyring:
gpg --verify wget2-*.tar.gz.sig