Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hxv-xg9w-4xg7

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.8

Описание

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header

EPSS

Процентиль: 28%
0.00351
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.8
nvd
6 месяцев назад

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header

CVSS3: 5.8
fstec
6 месяцев назад

Уязвимость графического пользовательского интерфейса операционных систем Fortinet FortiOS, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 28%
0.00351
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-444