Junglewise Threat Intelligence

CVE-2026-15146: GNU Wget SSRF via unvalidated FTP PASV IP address

CVE-2026-15146 · Severity: info · Published 2026-07-10

Technologies: Gnu Wget. Vendors: Gnu.

Executive brief

GNU Wget is a widely used command-line tool for downloading files from the internet. A security flaw in how it handles FTP connections allows a malicious server to trick Wget into connecting to different, potentially private internal systems instead of the intended file location. This could allow an attacker to scan internal networks, access private services, or steal data from systems that are not normally exposed to the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in GNU Wget versions 1.25.0 and earlier due to improper validation of FTP PASV and LPSV responses. When operating in FTP passive mode, Wget accepts the IP address and port provided by the server for the data connection without verifying if the IP matches the control connection's peer address. An attacker-controlled FTP server, or an HTTP server that redirects Wget to a malicious FTP URL, can exploit this to force Wget to establish a connection to internal network resources or localhost services. The issue was addressed by ensuring Wget rejects PASV/LPSV responses if the advertised address does not match the control connection's peer address.

Affected products

  • GNU Wget 1.25.0 and earlier

Timeline

  • 2026-05-27: disclosed: Vendor notified
  • 2026-07-05: patched: Fix committed to upstream master
  • 2026-07-10: advisory: Public disclosure and CVE assignment

References

Related threats