SB2026080638 - Improper neutralization of HTTP headers in SonicWall SonicOS
Published: August 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Neutralization of HTTP Headers for Scripting Syntax (CVE-ID: CVE-2026-0516)
CWE-ID: CWE-644 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to redirect firewall management users to arbitrary web domains.
The vulnerability exists due to improper neutralization of HTTP headers for scripting syntax in the SonicOS web management interface when handling HTTP requests with a manipulated Host header. A remote attacker can send a specially crafted request to redirect firewall management users to arbitrary web domains.
User interaction is required for a firewall management user to follow the malicious redirection.
Remediation
Install update from vendor's website.