DoS due to unsafe function in signal handler
Summary
A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.
| Version | Affected | Solution |
|---|---|---|
| FortiAnalyzer 8.0 | Not affected | Not Applicable |
| FortiAnalyzer 7.6 | 7.6.0 through 7.6.4 | Upgrade to 7.6.5 or above |
| FortiAnalyzer 7.4 | 7.4.0 through 7.4.8 | Upgrade to 7.4.9 or above |
| FortiAnalyzer 7.2 | 7.2 all versions | Migrate to a fixed release |
| FortiManager 8.0 | Not affected | Not Applicable |
| FortiManager 7.6 | 7.6.0 through 7.6.4 | Upgrade to 7.6.5 or above |
| FortiManager 7.4 | 7.4.0 through 7.4.8 | Upgrade to 7.4.9 or above |
| FortiManager 7.2 | 7.2 all versions | Migrate to a fixed release |
Acknowledgement
Internally discovered and reported by Loic Pantano of Fortinet PSIRTTimeline
2026-05-12: Initial publication