Release date:
2026-07-31 10:11:02 UTC
Description:
- CVE-2026-15146: validate the address advertised in the FTP PASV/LPSV response
against the control connection peer, preventing a malicious FTP server from
steering the data connection to an arbitrary host (SSRF)
Updated packages:
-
wget-1.21.1-8.el9_6.tuxcare.els3.x86_64.rpm
sha:504172e0c4a2a3cbed7944dc5d65f64c85c2e763680f76afa283ceb63068c460
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.