SB2026080638 - Improper neutralization of HTTP headers in SonicWall SonicOS



SB2026080638 - Improper neutralization of HTTP headers in SonicWall SonicOS

Published: August 6, 2026

Security Bulletin ID SB2026080638
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Neutralization of HTTP Headers for Scripting Syntax (CVE-ID: CVE-2026-0516)

CWE-ID: CWE-644 - Improper Neutralization of HTTP Headers for Scripting Syntax

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to redirect firewall management users to arbitrary web domains.

The vulnerability exists due to improper neutralization of HTTP headers for scripting syntax in the SonicOS web management interface when handling HTTP requests with a manipulated Host header. A remote attacker can send a specially crafted request to redirect firewall management users to arbitrary web domains.

User interaction is required for a firewall management user to follow the malicious redirection.


Remediation

Install update from vendor's website.