HTTP response splitting in FortiProxy and FortiOS - CVE-2025-62826

 

HTTP response splitting in FortiProxy and FortiOS - CVE-2025-62826

Published: July 14, 2026


Vulnerability identifier: #VU137530
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62826
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper neutralization of crlf sequences in http headers ('http response splitting') in captive portal authentication form. An attacker able can intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.


Affected software

FortiProxy
FortiOS

How to mitigate CVE-2025-62826

Install update from vendor's website.

FortiProxy - update to 7.6.5
FortiOS - update to 7.6.5

External References

Related Security Bulletins