CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6508.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.19.1" } ] } ]