Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Fortinet PSIRT

Header injection in Web Filter warning page

  • What: A header injection vulnerability in FortiOS and FortiProxy allows HTTP response splitting.
  • Impact: Attackers could inject arbitrary headers.
Read Full Article →

PSIRT Header injection in Web Filter warning page Summary An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Version Affected Solution FortiOS 8.0 Not affected Not Applicable FortiOS 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above FortiOS 7.4 7.4 all versions Migrate to a fixed release FortiOS 7.2 7.2 all versions Migrate to a fixed release FortiProxy 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.5 or above FortiProxy 7.4 7.4 all versions Migrate to a fixed release FortiProxy 7.2 7.2 all versions Migrate to a fixed release Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool Acknowledgement Fortinet is pleased to thank Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure. Timeline 2026-07-14: Initial publication IR Number FG-IR-26-152 Published Date Jul 14, 2026 Component OTHERS Severity Low Discovered External Attack Type Unauthenticated Known Exploited No CVSSv3 Score 3.4 Impact Execute unauthorized code or commands CVE ID CVE-2025-62675 Download CVRF CSAF

Share this article