FORTINET Security Advisory

Published Date: July 14, 2026

Advisory Summary

Fortinet has disclosed a security issue classified as Improper Neutralization of CRLF Sequences in HTTP Headers, also known as HTTP Response Splitting (CWE-113). This flaw affects FortiOS and FortiProxy products and could allow an attacker holding a valid web filter override token to inject arbitrary HTTP headers. The attack vector involves tricking a user into clicking a specially crafted link, which could enable various malicious activities such as web cache poisoning or cross-site scripting.

The vulnerability holds a CVSSv3 score of 3.4, indicating a moderate risk level but noteworthy due to its exploitation complexity involving social engineering. Fortinet has revised this security advisory on July 14, 2026, and it is critical for organizations using these products to verify their exposure and implement recommended patches or mitigations promptly.

Keeping infrastructure defenses updated continues to be essential in safeguarding the integrity of network communications and preventing exploitation of header injection attacks.

Reference: Vendor Advisory