{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/vex/2026/cve-2026-15146-els_os-centos-stream8els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T17:54:50Z",
      "generator": {
        "date": "2026-07-28T17:54:49Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-15146-ELS_OS-CENTOS-STREAM8ELS",
      "initial_release_date": "2026-07-10T19:17:00Z",
      "revision_history": [
        {
          "date": "2026-07-10T19:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T14:29:38Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T17:54:50Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.19.5-11.el8.x86_64",
                "product": {
                  "name": "wget-0:1.19.5-11.el8.x86_64",
                  "product_id": "wget-0:1.19.5-11.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/wget@1.19.5-11.el8?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
                  "product_id": "wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.19.5-11.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
                "product": {
                  "name": "wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
                  "product_id": "wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/wget@1.19.5-11.el8.tuxcare.els2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.19.5-11.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.19.5-11.el8.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els2.x86_64"
        },
        "product_reference": "wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.19.5-11.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:wget-0:1.19.5-11.el8.x86_64"
        },
        "product_reference": "wget-0:1.19.5-11.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
          "CentOS-Stream-8:wget-0:1.19.5-11.el8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T17:03:01.825281Z",
          "details": "This issue is only reachable when Wget runs an FTP passive-mode transfer against an attacker-controlled FTP server (or an HTTP endpoint that deliberately redirects to ftp://), allowing the attacker to steer just the FTP data-channel TCP connection to another host/port. The data channel does not carry application-layer requests from Wget, so practical impact is limited to basic outbound reachability/banners rather than arbitrary internal service interaction, with no code execution or privilege escalation. In centrally managed server/VM environments that fetch artifacts over HTTPS and avoid FTP or cross-scheme redirects, exposure is effectively nil and the CVE can be safely deprioritized.",
          "product_ids": [
            "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:wget-0:1.19.5-11.el8.tuxcare.els2.x86_64",
            "CentOS-Stream-8:wget-0:1.19.5-11.el8.x86_64"
          ]
        }
      ]
    }
  ]
}