{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: SSRF via unvalidated FTP PASV/LPSV response address\n     - debian/patches/CVE-2026-15146.patch: validate the PASV/LPSV response\n       address against the control connection peer in src/ftp-basic.c\n     - CVE-2026-15146",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784899129",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784899129"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu20.04els/advisories/2026/clsa-2026_1784899129.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-24T13:19:53Z",
      "generator": {
        "date": "2026-07-24T13:19:53Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1784899129",
      "initial_release_date": "2026-07-24T13:19:53Z",
      "revision_history": [
        {
          "date": "2026-07-24T13:19:53Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 20.04",
                "product": {
                  "name": "Ubuntu 20.04",
                  "product_id": "Ubuntu-20",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64",
                "product": {
                  "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64",
                  "product_id": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.20.3-1ubuntu2.1%2Btuxcare.els2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64",
                "product": {
                  "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64",
                  "product_id": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.20.3-1ubuntu2.1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64"
        },
        "product_reference": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64"
        },
        "product_reference": "wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64"
        ],
        "known_affected": [
          "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-24T13:18:54.726334Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1784899129",
          "product_ids": [
            "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els2.amd64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1784899129"
        },
        {
          "category": "none_available",
          "date": "2026-07-10T19:17:00Z",
          "details": "Affected",
          "product_ids": [
            "Ubuntu-20:wget-0:1.20.3-1ubuntu2.1+tuxcare.els1.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}