apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7443.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "3.3" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "1.7.13" } ] } ]