{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2026/cve-2026-15146-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-14T15:40:32Z",
      "generator": {
        "date": "2026-09-14T15:40:32Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-15146-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2026-07-10T19:17:00Z",
      "revision_history": [
        {
          "date": "2026-07-10T19:17:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-14T15:40:32Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-15146"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2.armel",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2.armel",
                  "product_id": "wget-0:1.21-1+deb11u2.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/wget@1.21-1%2Bdeb11u2?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2.arm64",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2.arm64",
                  "product_id": "wget-0:1.21-1+deb11u2.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/wget@1.21-1%2Bdeb11u2?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2.amd64",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2.amd64",
                  "product_id": "wget-0:1.21-1+deb11u2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/wget@1.21-1%2Bdeb11u2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
                  "product_id": "wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.21-1%2Bdeb11u2%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
                  "product_id": "wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.21-1%2Bdeb11u2%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
                "product": {
                  "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
                  "product_id": "wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/wget@1.21-1%2Bdeb11u2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.armel"
        },
        "product_reference": "wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2.armel as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2.armel"
        },
        "product_reference": "wget-0:1.21-1+deb11u2.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.arm64"
        },
        "product_reference": "wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2.arm64 as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2.arm64"
        },
        "product_reference": "wget-0:1.21-1+deb11u2.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.amd64"
        },
        "product_reference": "wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "wget-0:1.21-1+deb11u2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:wget-0:1.21-1+deb11u2.amd64"
        },
        "product_reference": "wget-0:1.21-1+deb11u2.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-15146",
      "notes": [
        {
          "category": "description",
          "text": "GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
          "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
          "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
          "Debian-11:wget-0:1.21-1+deb11u2.amd64",
          "Debian-11:wget-0:1.21-1+deb11u2.arm64",
          "Debian-11:wget-0:1.21-1+deb11u2.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-15146"
        },
        {
          "category": "external",
          "summary": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b",
          "url": "https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b"
        },
        {
          "category": "external",
          "summary": "https://kb.cert.org/vuls/id/564823",
          "url": "https://kb.cert.org/vuls/id/564823"
        },
        {
          "category": "external",
          "summary": "https://www.kb.cert.org/vuls/id/564823",
          "url": "https://www.kb.cert.org/vuls/id/564823"
        }
      ],
      "release_date": "2026-07-10T19:17:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-08T14:05:58.641122Z",
          "details": "This issue only applies when Wget is used in FTP passive mode against an attacker-controlled FTP endpoint (or after an HTTP→FTP redirect), so it does not affect ordinary HTTP/HTTPS downloads. The flaw merely causes Wget to open a TCP data socket to an arbitrary address/port; in passive FTP this stream is server-to-client and does not carry attacker‑crafted requests, providing no path to code execution and only low-value, blind SSRF consistent with the C:L/I:L/A:L impact. In centrally managed server/VM environments where Wget typically runs without elevated privileges, the realistic blast radius is small, making this a reasonable candidate to deprioritize.",
          "product_ids": [
            "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.amd64",
            "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.arm64",
            "Debian-11:wget-0:1.21-1+deb11u2+tuxcare.els1.armel",
            "Debian-11:wget-0:1.21-1+deb11u2.amd64",
            "Debian-11:wget-0:1.21-1+deb11u2.arm64",
            "Debian-11:wget-0:1.21-1+deb11u2.armel"
          ]
        }
      ]
    }
  ]
}