BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A)...
Moderate severity
Unreviewed
Published
Nov 10, 2025
to the GitHub Advisory Database
•
Updated Jun 2, 2026
Description
Published by the National Vulnerability Database
Nov 10, 2025
Published to the GitHub Advisory Database
Nov 10, 2025
Last updated
Jun 2, 2026
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
References