UBUNTU-CVE-2026-15146
GNU Wget versions listed do not validate the IP address returned by an FTP PASV response when operating in FTP passive mode. This flaw allows a malicious FTP server or an HTTP server redirecting to an FTP URL to redirect Wget's data connection to an arbitrary IP address and port. Exploitation can lead to server-side request forgery (SSRF), potentially enabling access to localhost services or internal network resources from the machine running Wget.
AI Analysis
Technical Summary
The vulnerability in GNU Wget arises from improper validation of the IP address provided by an FTP PASV response during FTP passive mode operations. This enables an attacker controlling an FTP server or an HTTP server redirecting to FTP to redirect Wget's data connection to an arbitrary IP and port. Consequently, this can be exploited to forge server-side requests (SSRF) from the affected host, potentially allowing access to internal or localhost services. The issue affects multiple specific Ubuntu package versions of Wget as enumerated. There is no vendor advisory or patch information provided in the input data.
Potential Impact
Exploitation of this vulnerability allows an attacker to perform SSRF attacks from the victim machine running Wget. This can lead to unauthorized access to internal network services or localhost resources that would otherwise be inaccessible externally. The impact includes potential confidentiality, integrity, and availability loss on internal services due to forged requests originating from the vulnerable host.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using Wget with untrusted FTP servers or HTTP servers that redirect to FTP URLs. Monitoring and restricting outbound FTP connections may reduce exposure.
UBUNTU-CVE-2026-15146
Description
GNU Wget versions listed do not validate the IP address returned by an FTP PASV response when operating in FTP passive mode. This flaw allows a malicious FTP server or an HTTP server redirecting to an FTP URL to redirect Wget's data connection to an arbitrary IP address and port. Exploitation can lead to server-side request forgery (SSRF), potentially enabling access to localhost services or internal network resources from the machine running Wget.
CVSS v3.1
Score 5.9medium
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in GNU Wget arises from improper validation of the IP address provided by an FTP PASV response during FTP passive mode operations. This enables an attacker controlling an FTP server or an HTTP server redirecting to FTP to redirect Wget's data connection to an arbitrary IP and port. Consequently, this can be exploited to forge server-side requests (SSRF) from the affected host, potentially allowing access to internal or localhost services. The issue affects multiple specific Ubuntu package versions of Wget as enumerated. There is no vendor advisory or patch information provided in the input data.
Potential Impact
Exploitation of this vulnerability allows an attacker to perform SSRF attacks from the victim machine running Wget. This can lead to unauthorized access to internal network services or localhost resources that would otherwise be inaccessible externally. The impact includes potential confidentiality, integrity, and availability loss on internal services due to forged requests originating from the vulnerable host.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using Wget with untrusted FTP servers or HTTP servers that redirect to FTP URLs. Monitoring and restricting outbound FTP connections may reduce exposure.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-15146
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b4f568715ace43db1ff1
Added to database: 07/16/2026, 10:39:49 UTC
Last enriched: 07/16/2026, 13:59:39 UTC
Last updated: 07/31/2026, 19:24:48 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.