Executive brief
Fortinet FortiOS and FortiProxy, which are used to manage and secure corporate network traffic, contain a security flaw in their web filtering component. An attacker could trick a user into clicking a malicious link to inject unauthorized information into the user's web session. While this requires the attacker to possess a specific security token and involves user interaction, it could be used to bypass certain security controls or mislead users.
Technical details
An HTTP Response Splitting vulnerability (CWE-113) exists in the Web Filter warning page of Fortinet FortiOS and FortiProxy. The flaw is caused by improper neutralization of CRLF sequences in HTTP headers. An attacker who possesses a valid web filter override token can exploit this by tricking a user into clicking a specially crafted link, leading to the injection of arbitrary headers. This is categorized as a low-severity issue due to the requirement for a valid token and user interaction (UI:R). Patches are available in FortiOS/FortiProxy versions 7.6.5 and above; users on 7.4 and 7.2 branches are advised to migrate to a fixed release.
Affected products
- Fortinet FortiOS 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
- Fortinet FortiProxy 7.6.0 through 7.6.4, 7.4 all versions, 7.2 all versions
Timeline
- 2026-07-14: advisory: Initial publication by Fortinet
- 2026-07-14: disclosed