惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
罗磊的独立博客
The Cloudflare Blog
V
V2EX
月光博客
月光博客
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
博客园 - 【当耐特】
T
Tailwind CSS Blog

CERT Recently Published Vulnerability Notes

CERT/CC Vulnerability Note VU#280377 CERT/CC Vulnerability Note VU#369093 CERT/CC Vulnerability Note VU#212479 CERT/CC Vulnerability Note VU#369611 CERT/CC Vulnerability Note VU#687587 CERT/CC Vulnerability Note VU#718077 CERT/CC Vulnerability Note VU#859658 CERT/CC Vulnerability Note VU#943094 CERT/CC Vulnerability Note VU#889462 CERT/CC Vulnerability Note VU#456290 CERT/CC Vulnerability Note VU#308749 CERT/CC Vulnerability Note VU#728712 CERT/CC Vulnerability Note VU#756733 CERT/CC Vulnerability Note VU#874418 CERT/CC Vulnerability Note VU#431093 CERT/CC Vulnerability Note VU#614868 CERT/CC Vulnerability Note VU#987105 CERT/CC Vulnerability Note VU#487613 CERT/CC Vulnerability Note VU#243636 CERT/CC Vulnerability Note VU#281278 CERT/CC Vulnerability Note VU#790363 CERT/CC Vulnerability Note VU#293714 CERT/CC Vulnerability Note VU#305509 CERT/CC Vulnerability Note VU#141367 CERT/CC Vulnerability Note VU#492466 CERT/CC Vulnerability Note VU#847406 CERT/CC Vulnerability Note VU#360868 CERT/CC Vulnerability Note VU#762226 CERT/CC Vulnerability Note VU#885548 CERT/CC Vulnerability Note VU#326070
CERT/CC Vulnerability Note VU#564823
2026-07-11 · via CERT Recently Published Vulnerability Notes

Overview

GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vulnerability has been remediated in a recent update by GNU; see the Solutions section below for resolution guidance.

Description

GNU Wget is a widely used command-line utility for retrieving content over HTTP, HTTPS, and FTP. When operating over FTP in passive mode, Wget relies on the server’s PASV response to determine which IP address and port to use for the data connection.

CVE-2026-15146 GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

This issue belongs to a known class of FTP PASV vulnerabilities such as CVE-2021-40491, which was previously remediated in GNU Inetutils.

Impact

A remote attacker controlling or influencing an FTP endpoint can induce Wget to establish connections to otherwise inaccessible internal network addresses. This may allow the attacker to retrieve service banners, access internal HTTP endpoints, or exfiltrate data from internal systems reachable by the victim host. Applications that embed Wget for automated retrieval are particularly susceptible, because the vulnerability may be triggered automatically through redirected requests and untrusted user-supplied URLs.

Solution

GNU Wget has remediated this issue in the 07/05/2026 commit 4f85853f641863d5915786a8413e1a213726a62b. Users are advised to update their version according to vendor guidance.

Acknowledgements

Thanks to Jeremy Brown for researching and reporting this vulnerability. This document was written by Molly Jaconski.

Vendor Information

Filter by content: Additional information available

 Sort by:


Other Information

CVE IDs: CVE-2026-15146
API URL: VINCE JSON | CSAF
Date Public: 2026-07-10
Date First Published: 2026-07-10
Date Last Updated: 2026-07-10 18:19 UTC
Document Revision: 1