Release date:
2026-08-11 22:45:54 UTC
Description:
- CVE-2026-15146: validate the address advertised in an FTP PASV/LPSV
response against the control connection's peer, so a malicious FTP
server cannot redirect the data connection to an arbitrary host (SSRF)
Updated packages:
-
wget-1.21.1-7.el9_2.tuxcare.els5.x86_64.rpm
sha:6355c9e390c475b20160da963c19b92fe4cfbe9243c3af19e33cb41434671d9b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.