Bug 2499143 (CVE-2026-15146) - CVE-2026-15146 wget: Wget: Server-Side Request Forgery via FTP PASV response IP address validation bypass
Summary: CVE-2026-15146 wget: Wget: Server-Side Request Forgery via FTP PASV response ...
Keywords:
Status: NEW
Alias: CVE-2026-15146
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2499186 2499187 2499188
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-10 19:02 UTC by OSIDB Bzimport
Modified: 2026-07-18 08:28 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-10 19:02:47 UTC
GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.


Note You need to log in before you can comment on or make changes to this bug.