Request smuggling attack in FortiOS

Summary

An HTTP request smuggling vulnerability [CWE-444] in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header

Version Affected Solution
FortiOS 7.6 7.6.0 Upgrade to 7.6.1 or above
FortiOS 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above
FortiOS 7.2 7.2 all versions Migrate to a fixed release
FortiOS 7.0 7.0 all versions Migrate to a fixed release
FortiOS 6.4 6.4.3 through 6.4.16 Migrate to a fixed release
Follow the recommended upgrade path using our tool at: https://docs.fortinet.com/upgrade-tool

This vulnerability only affects rules using a VIP to forward requests to a HTTP/1.1 server.

Acknowledgement

Discovered by Daobing Li from Fortinet R&D Team

Timeline

2026-02-10: Initial publication
2026-02-26: Added impact details.