CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons
CVE-2021-31879: wget Authorization header leak on cross-origin redirect via --header
CVE-2021-31879: Wget Authorization Header Leak on Cross-Origin Redirects
CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect
CVE-2020-11501: GnuTLS STEK left zero on first use (TOTP gating skips initial rotation)
CVE-2023-46218 — curl cookie mixed-case PSL bypass in Curl_cookie_add
CVE-2021-31879: wget Authorization header leak across cross-origin HTTP redirects
CVE-2021-31879: HTTP Redirect Authorization Header Leak in Wget v1.21
CVE-2018-20483: Wget stores credentials in extended file attributes (information-leak)
CVE-2018-20483: wget --xattr leaks URL credentials into extended file attributes
wget CVE-2018-20483: Information leak via embedded credentials in extended file attributes
CVE-2018-20483: Information Leak via Extended Attributes in wget xattr.c
CVE-2023-43115: Ghostscript IJS device bypasses SAFER path validation
CVE-2018-20483: wget leaks credentials in xattr metadata via URL_AUTH_SHOW
OpenClaw Anthropic adapter sanitizeTransportPayloadText corrupts thinking block signatures on replay
Better Auth getSession() crashes Next.js 15 Server Components with "Cookies can only be modified" error