DEBIAN-CVE-2026-15146

Source
https://security-tracker.debian.org/tracker/CVE-2026-15146
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15146.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-15146
Upstream
  • CVE-2026-15146
Published
2026-07-10T19:17:20Z
Modified
2026-09-14T17:02:46Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

References

Affected packages

Debian:12 / wget

Package

Name
wget
Purl
pkg:deb/debian/wget?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.21.3-1
1.21.3-1+deb12u1
1.21.4-1
1.24.5-1
1.24.5-2
1.25.0-1
1.25.0-2
1.25.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15146.json"

Debian:13 / wget

Package

Name
wget
Purl
pkg:deb/debian/wget?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.25.0-2
1.25.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15146.json"

Debian:14 / wget

Package

Name
wget
Purl
pkg:deb/debian/wget?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25.0-3

Affected versions

1.*
1.25.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-15146.json"