CVE-2025-60876
published 2025-11-10CVE-2025-60876: BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.29%
20.5th percentile
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| busybox | busybox | <= 1.37.0 | — |
| busybox | busybox | >= 0 < 1:1.37.0-8 | 1:1.37.0-8 |
| debian | busybox | < busybox 1:1.37.0-8 (forky) | busybox 1:1.37.0-8 (forky) |
| msrc | azl3_busybox_1.36.1-18_on_azure_linux_3.0 | — | — |
| msrc | azl3_busybox_1.36.1-19_on_azure_linux_3.0 | — | — |
| msrc | azl3_busybox_1.36.1-21_on_azure_linux_3.0 | — | — |
| msrc | azl3_busybox_1.36.1-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_busybox_1.36.1-23_on_azure_linux_3.0 | — | — |
| msrc | cbl2_busybox_1.35.0-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_busybox_1.35.0-16_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_busybox_1.35.0-18_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_msrc9.4CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-60876: BusyBox wget thru 1
osv·2025-11-10·CVSS 6.5
CVE-2025-60876 [MEDIUM] CVE-2025-60876: BusyBox wget thru 1
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
GHSA
GHSA-48hw-cv6f-mcpj: BusyBox wget thru 1
ghsa_unreviewed·2025-11-10
CVE-2025-60876 [MEDIUM] CWE-284 GHSA-48hw-cv6f-mcpj: BusyBox wget thru 1
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
Microsoft
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be
vendor_msrc·2025-11-11·CVSS 9.4
CVE-2025-60876 [MEDIUM] CWE-284 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
busybox: BusyBox wget: HTTP request-target allows header injection
vendor_redhat·2025-11-10·CVSS 6.5
CVE-2025-60876 [MEDIUM] CWE-93 busybox: BusyBox wget: HTTP request-target allows header injection
busybox: BusyBox wget: HTTP request-target allows header injection
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
A flaw was found in BusyBox wget. This vulnerability allows header injection via raw CR/LF and other C0 control bytes in the HTTP request-target. An attacker can exploit this by crafting a URL containing these control characters to inject arbitrary HTTP headers into the outgoing request, potentially leading to HTTP response splitting, cache poison
Debian
CVE-2025-60876: busybox - BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control by...
vendor_debian·2025·CVSS 6.5
CVE-2025-60876 [MEDIUM] CVE-2025-60876: busybox - BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control by...
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.37.0-8)
sid: resolved (fixed in 1:1.37.0-8)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htmhttps://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htmhttps://cert-portal.siemens.com/productcert/html/ssa-253495.html
2025-11-10
Published