Your message dated Fri, 24 Jul 2026 14:20:04 +0000
with message-id <[email protected]>
and subject line Bug#1142284: fixed in wget 1.25.0-3
has caused the Debian Bug report #1142284,
regarding wget: CVE-2026-15146
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142284: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142284
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: wget
Version: 1.25.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for wget.
CVE-2026-15146[0]:
| GNU Wget does not validate the IP address provided by an FTP PASV
| response while operating in FTP passive mode. A malicious FTP
| server, or an HTTP server that redirects to an FTP URL, can exploit
| this behavior to redirect Wget’s data connection to an arbitrary IP
| address and port. This allows an attacker to forge server-side
| requests (SSRF) from the machine running Wget, potentially accessing
| localhost services or internal network resources.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-15146
https://www.cve.org/CVERecord?id=CVE-2026-15146
[1]
https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: wget
Source-Version: 1.25.0-3
Done: Noël Köthe <[email protected]>
We believe that the bug you reported is fixed in the latest version of
wget, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Noël Köthe <[email protected]> (supplier of updated wget package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 24 Jul 2026 15:53:14 +0200
Source: wget
Architecture: source
Version: 1.25.0-3
Distribution: unstable
Urgency: medium
Maintainer: Noël Köthe <[email protected]>
Changed-By: Noël Köthe <[email protected]>
Closes: 1142284
Changes:
wget (1.25.0-3) unstable; urgency=medium
.
* patch from upstream git to fix CVE-2026-15146 a problem with IP validation
in FTP PASV. closes: Bug#1142284
Checksums-Sha1:
edb897463f9e59c8fa481ca103736f2efe7c9c27 2032 wget_1.25.0-3.dsc
d6f9f1fe408e459ca4475745186c04148f719dfe 29248 wget_1.25.0-3.debian.tar.xz
bd1830cde0ab2f1b7440d8e44422b385a7a3ed8f 7923 wget_1.25.0-3_amd64.buildinfo
Checksums-Sha256:
d031f731bdae0a5a5ab77a56531b21557f6e3875c523cd50b633b35354b0e2c4 2032
wget_1.25.0-3.dsc
e06c0a278de51507b08080e2fd1ad2cb069b77c45ef8475fc3975d68b0105c73 29248
wget_1.25.0-3.debian.tar.xz
7c5dd496f151ab66f4be472e49c8f9d9cca0dfe412bea04df165be4637695261 7923
wget_1.25.0-3_amd64.buildinfo
Files:
b0cf99594e5fcb5b44942cba17f6425a 2032 web standard wget_1.25.0-3.dsc
7ab0214ed19d996a4d5e6110b13507bb 29248 web standard wget_1.25.0-3.debian.tar.xz
e7e136227ad102cd9af4b42a9b3c609a 7923 web standard
wget_1.25.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEpF5AXAxsgPE/8VIXaMB4voj4DNoFAmpjb5QACgkQaMB4voj4
DNoTTg//cZv9fjuuvbIwYy5m9e1GCd+6RodcIE3aUD8b/mXCGhzoSx5dieF7qRzS
K89BjeCcRhhhSoBdvas213uIUCEPoovWY99RB41bafhT1DjKIcokCkof5/iSnKae
c9bvw3v2TFeFRoVYSbQBfV4pnFBpxyAgE/MkBGOhPpKGS5Si0fDMAVdKag6BhBly
s9NDENf9GB+O+2w5QwqZy1h3LjYxv6fJvIPm14odYWy4zAYFz7829ugSUJ+OfQde
Ut0ePAu8/c4Q0I1tadwirBumT/mB2wNSQzJ5kW1nneADIKtVuSHUbLnn6/Me/NUQ
cS86P+ds5u7lC+PO2ysLJbwQR6HwzCZWNRIYUKXlXXVqW5HSodgWpWzqgyEaKh/K
uw6qhiTp2td7QoWPFJWVRSnr6zAzT4L1y3mFJDJE3/q5Dh0LARefd+83BrthCcIZ
UcR001haXMkYTsXDMTMx8Z+5SZfroJmYbhyLVMPlxG06eulDc0EY8mi0thEq3kAe
0RHw6shExTUw7v1kN82/7T2Pbc4BLScrgd5qeR6f90El6fB6sv03w42CxYgjzHFB
rc0ASRKOE7NE+B7sYI1in1uGZ6kcWJ2h75dPIRkQxnzEbnmCN7tVo93a/AgwPuuJ
2URI5mb05FW6alCzsBhaDyWHvqEAinAw0HAUFd0do84uXrZlVc8=
=SQPf
-----END PGP SIGNATURE-----
pgpubqy1EpPfe.pgp
Description: PGP signature
--- End Message ---