{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian10els/vex/2026/cve-2026-15146-els_os-debian10els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-31T20:48:18Z",
      "generator": {
        "date": "2026-07-31T20:48:17Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-15146-ELS_OS-DEBIAN10ELS",
      "initial_release_date": "2026-07-10T19:17:00Z",
      "revision_history": [
        {
          "date": "2026-07-10T19:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-31T15:04:28Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-31T20:48:18Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 10",
                "product": {
                  "name": "Debian 10",
                  "product_id": "Debian-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.20.1-1.1.amd64",
                "product": {
                  "name": "wget-0:1.20.1-1.1.amd64",
                  "product_id": "wget-0:1.20.1-1.1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/wget@1.20.1-1.1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.20.1-1.1+tuxcare.els2.amd64",
                "product": {
                  "name": "wget-0:1.20.1-1.1+tuxcare.els2.amd64",
                  "product_id": "wget-0:1.20.1-1.1+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.20.1-1.1%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.20.1-1.1+tuxcare.els1.amd64",
                "product": {
                  "name": "wget-0:1.20.1-1.1+tuxcare.els1.amd64",
                  "product_id": "wget-0:1.20.1-1.1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.20.1-1.1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.20.1-1.1+tuxcare.els2.amd64 as a component of Debian 10",
          "product_id": "Debian-10:wget-0:1.20.1-1.1+tuxcare.els2.amd64"
        },
        "product_reference": "wget-0:1.20.1-1.1+tuxcare.els2.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.20.1-1.1+tuxcare.els1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:wget-0:1.20.1-1.1+tuxcare.els1.amd64"
        },
        "product_reference": "wget-0:1.20.1-1.1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.20.1-1.1.amd64 as a component of Debian 10",
          "product_id": "Debian-10:wget-0:1.20.1-1.1.amd64"
        },
        "product_reference": "wget-0:1.20.1-1.1.amd64",
        "relates_to_product_reference": "Debian-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-10:wget-0:1.20.1-1.1+tuxcare.els1.amd64",
          "Debian-10:wget-0:1.20.1-1.1+tuxcare.els2.amd64",
          "Debian-10:wget-0:1.20.1-1.1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-31T18:39:01.372855Z",
          "details": "Deprioritize: Exploitation requires the host to actively invoke Wget against an attacker-controlled FTP endpoint (or follow an unusual HTTP→FTP redirect) so that FTP passive mode is used; there is no remote, unauthenticated trigger and no privilege escalation. The flaw only forces Wget to open an outbound TCP data connection to an arbitrary IP:port, yielding at most limited SSRF/port-discovery with low confidentiality, integrity, and availability impact and no code execution. Because standard server/VM workflows retrieve artifacts via HTTP/HTTPS or package managers, the vulnerable FTP passive-mode path is typically not exercised in managed enterprise environments, making real-world risk low.",
          "product_ids": [
            "Debian-10:wget-0:1.20.1-1.1+tuxcare.els1.amd64",
            "Debian-10:wget-0:1.20.1-1.1+tuxcare.els2.amd64",
            "Debian-10:wget-0:1.20.1-1.1.amd64"
          ]
        }
      ]
    }
  ]
}