#1142284 wget: CVE-2026-15146

Package:
src:wget
Source:
src:wget
Submitter:
Salvatore Bonaccorso
Date:
2026-07-24 14:23:03 UTC
Severity:
normal
Tags:
#1142284#5
Date:
2026-07-17 06:47:41 UTC
From:
To:
Hi,

The following vulnerability was published for wget.

CVE-2026-15146[0]:
| GNU Wget does not validate the IP address provided by an FTP PASV
| response while operating in FTP passive mode. A malicious FTP
| server, or an HTTP server that redirects to an FTP URL, can exploit
| this behavior to redirect Wget’s data connection to an arbitrary IP
| address and port. This allows an attacker to forge server-side
| requests (SSRF) from the machine running Wget, potentially accessing
| localhost services or internal network resources.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15146
https://www.cve.org/CVERecord?id=CVE-2026-15146
[1] https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142284#10
Date:
2026-07-24 14:20:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
wget, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142284@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Noël Köthe <noel@debian.org> (supplier of updated wget package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 24 Jul 2026 15:53:14 +0200
Source: wget
Architecture: source
Version: 1.25.0-3
Distribution: unstable
Urgency: medium
Maintainer: Noël Köthe <noel@debian.org>
Changed-By: Noël Köthe <noel@debian.org>
Closes: 1142284
Changes:
 wget (1.25.0-3) unstable; urgency=medium
 .
   * patch from upstream git to fix CVE-2026-15146 a problem with IP validation in FTP PASV. closes: Bug#1142284
Checksums-Sha1:
 edb897463f9e59c8fa481ca103736f2efe7c9c27 2032 wget_1.25.0-3.dsc
 d6f9f1fe408e459ca4475745186c04148f719dfe 29248 wget_1.25.0-3.debian.tar.xz
 bd1830cde0ab2f1b7440d8e44422b385a7a3ed8f 7923 wget_1.25.0-3_amd64.buildinfo
Checksums-Sha256:
 d031f731bdae0a5a5ab77a56531b21557f6e3875c523cd50b633b35354b0e2c4 2032 wget_1.25.0-3.dsc
 e06c0a278de51507b08080e2fd1ad2cb069b77c45ef8475fc3975d68b0105c73 29248 wget_1.25.0-3.debian.tar.xz
 7c5dd496f151ab66f4be472e49c8f9d9cca0dfe412bea04df165be4637695261 7923 wget_1.25.0-3_amd64.buildinfo
Files:
 b0cf99594e5fcb5b44942cba17f6425a 2032 web standard wget_1.25.0-3.dsc
 7ab0214ed19d996a4d5e6110b13507bb 29248 web standard wget_1.25.0-3.debian.tar.xz
 e7e136227ad102cd9af4b42a9b3c609a 7923 web standard wget_1.25.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpF5AXAxsgPE/8VIXaMB4voj4DNoFAmpjb5QACgkQaMB4voj4
DNoTTg//cZv9fjuuvbIwYy5m9e1GCd+6RodcIE3aUD8b/mXCGhzoSx5dieF7qRzS
K89BjeCcRhhhSoBdvas213uIUCEPoovWY99RB41bafhT1DjKIcokCkof5/iSnKae
c9bvw3v2TFeFRoVYSbQBfV4pnFBpxyAgE/MkBGOhPpKGS5Si0fDMAVdKag6BhBly
s9NDENf9GB+O+2w5QwqZy1h3LjYxv6fJvIPm14odYWy4zAYFz7829ugSUJ+OfQde
Ut0ePAu8/c4Q0I1tadwirBumT/mB2wNSQzJ5kW1nneADIKtVuSHUbLnn6/Me/NUQ
cS86P+ds5u7lC+PO2ysLJbwQR6HwzCZWNRIYUKXlXXVqW5HSodgWpWzqgyEaKh/K
uw6qhiTp2td7QoWPFJWVRSnr6zAzT4L1y3mFJDJE3/q5Dh0LARefd+83BrthCcIZ
UcR001haXMkYTsXDMTMx8Z+5SZfroJmYbhyLVMPlxG06eulDc0EY8mi0thEq3kAe
0RHw6shExTUw7v1kN82/7T2Pbc4BLScrgd5qeR6f90El6fB6sv03w42CxYgjzHFB
rc0ASRKOE7NE+B7sYI1in1uGZ6kcWJ2h75dPIRkQxnzEbnmCN7tVo93a/AgwPuuJ
2URI5mb05FW6alCzsBhaDyWHvqEAinAw0HAUFd0do84uXrZlVc8=
=SQPf
-----END PGP SIGNATURE-----