CVE-2017-6508: GNU Wget
Medium severity, CVSS 6.1. EPSS: 2.9% chance of exploitation in the next 30 days.
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
Affected products
- GNU Wget: up to and including 1.19.1
Published 2017-03-07. Last modified 2026-06-17.