Request smuggling attack in FortiOS
Summary
An HTTP request smuggling vulnerability [CWE-444] in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header
| Version | Affected | Solution |
|---|---|---|
| FortiOS 7.6 | 7.6.0 | Upgrade to 7.6.1 or above |
| FortiOS 7.4 | 7.4.0 through 7.4.9 | Upgrade to 7.4.10 or above |
| FortiOS 7.2 | 7.2 all versions | Migrate to a fixed release |
| FortiOS 7.0 | 7.0 all versions | Migrate to a fixed release |
| FortiOS 6.4 | 6.4.3 through 6.4.16 | Migrate to a fixed release |
This vulnerability only affects rules using a VIP to forward requests to a HTTP/1.1 server.
Acknowledgement
Discovered by Daobing Li from Fortinet R&D TeamTimeline
2026-02-10: Initial publication2026-02-26: Added impact details.