Source: wget Version: 1.25.0-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for wget. CVE-2026-15146[0]: | GNU Wget does not validate the IP address provided by an FTP PASV | response while operating in FTP passive mode. A malicious FTP | server, or an HTTP server that redirects to an FTP URL, can exploit | this behavior to redirect Wget’s data connection to an arbitrary IP | address and port. This allows an attacker to forge server-side | requests (SSRF) from the machine running Wget, potentially accessing | localhost services or internal network resources. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15146 https://www.cve.org/CVERecord?id=CVE-2026-15146 [1] https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b Please adjust the affected versions in the BTS as needed. Regards, Salvatore

