Source: wget
Version: 1.25.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for wget.

CVE-2026-15146[0]:
| GNU Wget does not validate the IP address provided by an FTP PASV
| response while operating in FTP passive mode. A malicious FTP
| server, or an HTTP server that redirects to an FTP URL, can exploit
| this behavior to redirect Wget’s data connection to an arbitrary IP
| address and port. This allows an attacker to forge server-side
| requests (SSRF) from the machine running Wget, potentially accessing
| localhost services or internal network resources.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15146
    https://www.cve.org/CVERecord?id=CVE-2026-15146
[1] 
https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to