CVE-2016-7098: GNU Wget
High severity, CVSS 8.1. EPSS: 7.5% chance of exploitation in the next 30 days.
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.
Affected products
- GNU Wget: up to and including 1.17
Published 2016-09-26. Last modified 2026-06-17.