[CLSA-2026:1784899129] Fix CVE(s): CVE-2026-15146
Type:
security
Severity:
Moderate
Release date:
2026-07-24 13:19:13 UTC
Description:
* SECURITY UPDATE: SSRF via unvalidated FTP PASV/LPSV response address - debian/patches/CVE-2026-15146.patch: validate the PASV/LPSV response address against the control connection peer in src/ftp-basic.c - CVE-2026-15146
CVEs fixed:
Updated packages:
  • wget_1.20.3-1ubuntu2.1+tuxcare.els2_amd64.deb
    sha:56df899c800875fc62194d392e3d07dcd5185f7e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.