FORTINET Security Advisory
Published Date: Not specified
Advisory Summary
🔎 ⚙️ Content-Encoding WAF Evasion — FortiWeb (PSIRT FG-IR-26-157)
- FortiWeb WAF has a vulnerability where an incomplete set of disallowed inputs (CWE-184) may let an unauthenticated attacker bypass existing WAF policies.
- The issue is tied to content encoding behaviors, meaning carefully crafted requests may evade enforcement.
- Policy bypass can result in requests that should be blocked being allowed.
- This can weaken protections around common attack paths (e.g., payload filtering, request validation, and rule enforcement), increasing exposure to application-layer attacks.
- Check your FortiWeb deployment version and whether it is covered by the remediation for FG-IR-26-157.
- Prioritize patching and/or mitigations immediately, especially for internet-facing WAF instances.
- Validate with internal testing by attempting the category of bypass using your application’s real request patterns (as applicable), then confirm WAF logging/rule hits.
- Review WAF logs for suspicious request variants that differ in encoding/content headers from normal traffic.
- Ensure any compensating controls (WAF rule tuning, strict request normalization, upstream filtering) are in place until systems are patched.
- Confirm you’re on the latest FortiWeb security updates referenced by the PSIRT advisory.
-184
Reference: Vendor Advisory