{
  "document": {
    "aggregate_severity": {
      "text": "Moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-15146: validate the address advertised in the FTP PASV/LPSV response\n  against the control connection peer, preventing a malicious FTP server from\n  steering the data connection to an arbitrary host (SSRF)",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/tuxcare9.6esu/advisories/2026/clsa-2026_1785492652.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-17T15:26:59Z",
      "generator": {
        "date": "2026-08-17T15:26:59Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1785492652",
      "initial_release_date": "2026-07-31T10:11:33Z",
      "revision_history": [
        {
          "date": "2026-07-31T10:11:33Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-17T15:26:59Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "wget: Fix of CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.6",
                "product": {
                  "name": "AlmaLinux 9.6",
                  "product_id": "AlmaLinux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Rocky Linux 9.6",
                "product": {
                  "name": "Rocky Linux 9.6",
                  "product_id": "Rocky Linux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:resf:rocky_linux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Rocky Linux"
          }
        ],
        "category": "vendor",
        "name": "Rocky Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
                  "product_id": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-8.el9_6.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
                "product": {
                  "name": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
                  "product_id": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.21.1-8.el9_6.tuxcare.els2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
        },
        "product_reference": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
        },
        "product_reference": "wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
        },
        "product_reference": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
        },
        "product_reference": "wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-58472",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-58472"
        },
        {
          "category": "external",
          "summary": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812",
          "url": "https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding",
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"
        }
      ],
      "release_date": "2026-07-07T19:50:53Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-31T10:10:54.780130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652"
        },
        {
          "category": "none_available",
          "date": "2026-07-07T19:50:53Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-58471",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-58471"
        },
        {
          "category": "external",
          "summary": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee",
          "url": "https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c",
          "url": "https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"
        }
      ],
      "release_date": "2026-07-07T19:47:47Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-31T10:10:54.780130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652"
        },
        {
          "category": "none_available",
          "date": "2026-07-07T19:47:47Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
          "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-31T10:10:54.780130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els3.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1785492652"
        },
        {
          "category": "none_available",
          "date": "2026-07-10T19:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64",
            "Rocky Linux-9.6:wget-0:1.21.1-8.el9_6.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}