CVE-2017-6508: GNU Wget

Medium severity, CVSS 6.1. EPSS: 2.9% chance of exploitation in the next 30 days.

CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.

Affected products

  • GNU Wget: up to and including 1.19.1

Published 2017-03-07. Last modified 2026-06-17.