An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-26-152 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Jul 2026, 18:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet
Fortinet fortiproxy Fortinet fortios |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-26-152 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
14 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 16:16
Updated : 2026-07-14 18:45
NVD link : CVE-2025-62675
Mitre link : CVE-2025-62675
CVE.ORG link : CVE-2025-62675
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
CWE
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
