CVE-2019-5953: wget heap buffer overflow in do_conversion via incorrect E2BIG handling
CVE-2021-31879: wget Authorization header leak on cross-origin redirect via --header
CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect
CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)
CVE-2018-20483: wget --xattr leaks URL credentials into user.xdg.origin.url extended attribute
CVE-2017-13089: wget skip_short_body stack overflow via negative HTTP chunk size (signed strtol + SIZE_MAX read)
CVE-2017-13089: wget skip_short_body() stack overflow via negative chunked size
CVE-2024-38428: wget url_skip_credentials semicolon causes hostname confusion
CVE-2024-38428: GNU Wget url_skip_credentials mishandles ';' in userinfo, enabling hostname confusion
CVE-2024-38428: URL parser hostname confusion via multiple @ characters in userinfo
CVE-2019-5953: wget 1.20.1 heap buffer overflow in reencode_escapes() URL handling
CVE-2019-5953: heap buffer overflow in wget iri.c do_conversion
CVE-2021-31879: wget Authorization header leak across cross-origin HTTP redirects
CVE-2021-31879: wget leaks Authorization across origin on redirect
CVE-2021-31879: HTTP Redirect Authorization Header Leak in Wget v1.21
CVE-2018-20483: wget --xattr leaks URL credentials into extended file attributes
CVE-2018-20483: wget --xattr leaks Basic-auth credentials via user.xdg.origin.url
CVE-2018-20483: Information Leak via Extended File Attributes in wget
CVE-2017-13089: wget skip_short_body stack overflow via negative chunked transfer encoding size
CVE-2017-13089: Stack-overflow in wget HTTP chunked transfer encoding parsing