๐Ÿ” CVE Alert

CVE-2025-60876

MEDIUM 6.5
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).

Vendor n/a
Product n/a
Published Nov 10, 2025
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new medium vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.busybox.net: https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm lists.busybox.net: https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm gist.github.com: https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092 cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-253495.html