PT-2026-57263 · Gnu+2 · Wget+2

CVE-2026-15146

·

Published

2026-07-10

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Wget versions prior to 1.25.1
Description GNU Wget fails to validate the IP address provided by an FTP PASV response when operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect the data connection to an arbitrary IP address and port. This leads to Server-Side Request Forgery (SSRF), a technique where an attacker induces a server-side application to make requests to an unintended location, potentially allowing access to localhost services or internal network resources.
Recommendations Update GNU Wget to the latest patched version. Implement robust egress filtering and network segmentation to limit the potential impact of the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-15146
ECHO-F6C6-54F8-2E56
OESA-2026-3152
OPENSUSE-SU-2026:11303-1
OPENSUSE-SU-2026:21665-1
SUSE-SU-2026:23053-1
SUSE-SU-2026:23163-1
SUSE-SU-2026:23297-1
SUSE-SU-2026:23326-1
SUSE-SU-2026:3148-1
SUSE-SU-2026:3205-1
SUSE-SU-2026:3206-1
USN-8572-1

Affected Products

Linuxmint
Ubuntu
Wget