[CLSA-2026:1784815431] Fix CVE(s): CVE-2026-15146
Type:
security
Severity:
Moderate
Release date:
2026-07-23 14:04:17 UTC
Description:
* SECURITY UPDATE: SSRF via unvalidated FTP PASV/LPSV response address - debian/patches/CVE-2026-15146.patch: validate the PASV/LPSV response address against the control connection peer in src/ftp-basic.c - CVE-2026-15146
CVEs fixed:
Updated packages:
  • wget_1.19.4-1ubuntu2.2+tuxcare.els3_amd64.deb
    sha:9c1985098388d63f07e736623fef2224780be92f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.