CVE-2025-60876

ADVISORY - nist

Summary

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).

EPSS Score: 0.00052 (0.164)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Access Control

ADVISORY - redhat

Improper Neutralization of CRLF Sequences ('CRLF Injection')


Alpine

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
alpine/busyboxapkalpine3.21<=1.37.0-r13Not yet available
alpine/busyboxapkalpine3.23<=1.37.0-r30Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r2Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r22Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r27Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r30Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r31Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r24Not yet available
alpine/busyboxapkalpineedge<=1.34.0_r0Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r28Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r20Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r18Not yet available
alpine/busyboxapkalpineedge<=1.29.3-r10Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r30Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r21Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r28Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r25Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r7Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r29Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r17Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r29Not yet available
alpine/busyboxapkalpineedge<=1.34.0-r0Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r13Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r12Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r24Not yet available
alpine/busyboxapkalpineedge<=1.28.3-r2Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r19Not yet available
alpine/busyboxapkalpineedge<=1.33.0-r5Not yet available
alpine/busyboxapkalpineedge<=1.30.1-r2Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r32Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r31Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r26Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r15Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r23Not yet available
alpine/busyboxapkalpineedge<=1.27.2-r4Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r14Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r10Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r27Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r27Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r25Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r22Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r29Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r16Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r26Not yet available
alpine/busyboxapkalpineedge<=1.37.0-r23Not yet available
alpine/busyboxapkalpineedge<=1.36.1-r30Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r25Not yet available
alpine/busyboxapkalpineedge<=1.35.0-r28Not yet available
alpine/busyboxapkalpine3.21<=1.27.2-r4Not yet available
alpine/busyboxapkalpine3.21<=1.28.3-r2Not yet available
alpine/busyboxapkalpine3.21<=1.29.3-r10Not yet available
alpine/busyboxapkalpine3.21<=1.30.1-r2Not yet available
alpine/busyboxapkalpine3.21<=1.33.0-r5Not yet available
alpine/busyboxapkalpine3.21<=1.34.0-r0Not yet available
alpine/busyboxapkalpine3.21<=1.35.0-r17Not yet available
alpine/busyboxapkalpine3.21<=1.35.0-r7Not yet available
alpine/busyboxapkalpine3.21<=1.36.1-r2Not yet available
alpine/busyboxapkalpine3.21<=1.36.1-r25Not yet available
alpine/busyboxapkalpine3.21<=1.36.1-r27Not yet available
alpine/busyboxapkalpine3.21<=1.36.1-r30Not yet available
alpine/busyboxapkalpine3.21<=1.37.0-r14Not yet available
alpine/busyboxapkalpine3.20<=1.27.2-r4Not yet available
alpine/busyboxapkalpine3.20<=1.28.3-r2Not yet available
alpine/busyboxapkalpine3.20<=1.29.3-r10Not yet available
alpine/busyboxapkalpine3.20<=1.30.1-r2Not yet available
alpine/busyboxapkalpine3.20<=1.33.0-r5Not yet available
alpine/busyboxapkalpine3.20<=1.34.0-r0Not yet available
alpine/busyboxapkalpine3.20<=1.35.0-r17Not yet available
alpine/busyboxapkalpine3.20<=1.35.0-r7Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r2Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r25Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r27Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r28Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r29Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r30Not yet available
alpine/busyboxapkalpine3.20<=1.36.1-r31Not yet available
alpine/busyboxapkalpine3.22<=1.27.2-r4Not yet available
alpine/busyboxapkalpine3.22<=1.28.3-r2Not yet available
alpine/busyboxapkalpine3.22<=1.29.3-r10Not yet available
alpine/busyboxapkalpine3.22<=1.30.1-r2Not yet available
alpine/busyboxapkalpine3.22<=1.33.0-r5Not yet available
alpine/busyboxapkalpine3.22<=1.34.0-r0Not yet available
alpine/busyboxapkalpine3.22<=1.35.0-r17Not yet available
alpine/busyboxapkalpine3.22<=1.35.0-r7Not yet available
alpine/busyboxapkalpine3.22<=1.36.1-r2Not yet available
alpine/busyboxapkalpine3.22<=1.36.1-r25Not yet available
alpine/busyboxapkalpine3.22<=1.36.1-r27Not yet available
alpine/busyboxapkalpine3.22<=1.36.1-r30Not yet available
alpine/busyboxapkalpine3.22<=1.37.0-r19Not yet available
alpine/busyboxapkalpine3.22<=1.37.0-r20Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.5medium

Debian

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Ubuntu

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Red Hat

CREATED

UPDATED

EXPLOITABILITY SCORE

2.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.4low

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-hgjv-8vrq-5jv9

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-3729-6w87-2929

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY