Release date:
2026-07-24 13:19:13 UTC
Description:
* SECURITY UPDATE: SSRF via unvalidated FTP PASV/LPSV response address
- debian/patches/CVE-2026-15146.patch: validate the PASV/LPSV response
address against the control connection peer in src/ftp-basic.c
- CVE-2026-15146
Updated packages:
-
wget_1.20.3-1ubuntu2.1+tuxcare.els2_amd64.deb
sha:56df899c800875fc62194d392e3d07dcd5185f7e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.