CVE-2016-7098: GNU Wget

High severity, CVSS 8.1. EPSS: 7.5% chance of exploitation in the next 30 days.

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.

Affected products

  • GNU Wget: up to and including 1.17

Published 2016-09-26. Last modified 2026-06-17.