{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-15146: validate the address advertised in an FTP PASV/LPSV\n  response against the control connection's peer, so a malicious FTP\n  server cannot redirect the data connection to an arbitrary host (SSRF)",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1786488345",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1786488345"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/advisories/2026/clsa-2026_1786488345.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-11T22:46:22Z",
      "generator": {
        "date": "2026-08-11T22:46:22Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1786488345",
      "initial_release_date": "2026-08-11T22:46:22Z",
      "revision_history": [
        {
          "date": "2026-08-11T22:46:22Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "wget: Fix of CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64",
                  "product_id": "wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-7.el9_2.tuxcare.els5?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64",
                  "product_id": "wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-7.el9_2.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
                  "product_id": "wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-7.el9.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
                  "product_id": "wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-7.el9.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
                  "product_id": "wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-7.el9.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64"
        },
        "product_reference": "wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64"
        },
        "product_reference": "wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-7.el9.tuxcare.els3.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els3.x86_64"
        },
        "product_reference": "wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-7.el9.tuxcare.els2.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els2.x86_64"
        },
        "product_reference": "wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-7.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-11T22:45:47.074840Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1786488345",
          "product_ids": [
            "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els5.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1786488345"
        },
        {
          "category": "none_available",
          "date": "2026-07-10T19:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:wget-0:1.21.1-7.el9.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:wget-0:1.21.1-7.el9_2.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}