Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-15146

около 1 месяца назад

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-15146

около 1 месяца назад

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-15146

около 1 месяца назад

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-15146

около 1 месяца назад

GNU Wget does not validate the IP address provided by an FTP PASV resp ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-77jw-q7w3-q2hw

около 1 месяца назад

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3205-1

26 дней назад

Security update for wget

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3206-1

26 дней назад

Security update for wget

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3148-1

28 дней назад

Security update for wget

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-15146

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-15146

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-15146

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-15146

GNU Wget does not validate the IP address provided by an FTP PASV resp ...

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-77jw-q7w3-q2hw

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3205-1

Security update for wget

26 дней назад
suse-cvrf логотип
SUSE-SU-2026:3206-1

Security update for wget

26 дней назад
suse-cvrf логотип
SUSE-SU-2026:3148-1

Security update for wget

28 дней назад

Уязвимостей на страницу