CVE-2025-55018
FortiOS vulnerability analysis and mitigation

Overview

CVE-2025-55018 is an HTTP Request Smuggling vulnerability (CWE-444) in Fortinet FortiOS that allows unauthenticated attackers to smuggle unlogged HTTP requests through firewall policies via a specially crafted header. The vulnerability affects FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 (all versions), FortiOS 7.0 (all versions), and FortiOS 6.4.3 through 6.4.16. It was initially published on February 10, 2026, with impact details added on February 26, 2026. The CVSS v3.1 base score is 5.8 (Medium) per NVD, while Fortinet's advisory lists a CVSSv3 score of 5.2 (Medium) (FortiGuard Advisory).

Technical details

The vulnerability is classified as CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling), where FortiOS inconsistently parses HTTP request headers, enabling an attacker to craft requests that are interpreted differently by the FortiOS firewall and the backend HTTP/1.1 server. Exploitation requires that firewall rules use a Virtual IP (VIP) to forward requests to an HTTP/1.1 backend server — this is a key precondition. By sending a specially crafted HTTP header, an unauthenticated remote attacker can cause a secondary, unlogged HTTP request to be forwarded through firewall policies, effectively bypassing inspection and logging. The vulnerability was discovered internally by Daobing Li from the Fortinet R&D Team (FortiGuard Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to smuggle HTTP requests through FortiOS firewall policies without those requests being logged, enabling policy evasion and integrity compromise. The primary impact is on integrity (low) with a changed scope, meaning the attacker can influence resources beyond the vulnerable component itself — specifically, backend servers protected by the firewall. There is no direct confidentiality or availability impact, but the ability to bypass firewall inspection and logging undermines security monitoring and could facilitate further attacks against backend systems that rely on the firewall for protection (FortiGuard Advisory, Feedly).

Exploitability

As of the advisory date, Fortinet has confirmed this vulnerability is not known to be exploited in the wild (FortiGuard Advisory). The EPSS score is approximately 0.031% (0.000310), indicating a low probability of exploitation in the near term. No public proof-of-concept exploit code or threat actor attribution has been identified. The vulnerability is detectable via Qualys scanner (detection ID 591683) and Tenable Nessus (plugin 298523). The attack requires no authentication and no user interaction, but is limited to environments where VIP-based HTTP/1.1 forwarding rules are configured.

Exploitation steps

  1. Reconnaissance: Identify FortiOS deployments running affected versions (7.6.0, 7.4.0–7.4.9, 7.2.x, 7.0.x, or 6.4.3–6.4.16) that expose HTTP/HTTPS services with VIP-based forwarding rules to HTTP/1.1 backend servers.
  2. Identify VIP-forwarded endpoints: Probe the target FortiOS firewall to identify endpoints where Virtual IP (VIP) rules forward traffic to HTTP/1.1 backend servers, as exploitation is limited to this configuration.
  3. Craft smuggled request: Construct a specially crafted HTTP request with ambiguous or conflicting headers (e.g., conflicting Content-Length and Transfer-Encoding headers, or malformed chunked encoding) designed to be interpreted differently by FortiOS and the backend server.
  4. Send the malicious request: Transmit the crafted HTTP request to the FortiOS firewall. FortiOS processes the outer request normally and forwards what it interprets as a single request, while the backend HTTP/1.1 server interprets the payload as containing an additional, embedded request.
  5. Achieve policy bypass: The smuggled secondary request reaches the backend server without being subject to FortiOS firewall policy inspection or logging, potentially accessing restricted resources or injecting malicious content into subsequent legitimate user sessions (FortiGuard Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests with conflicting or malformed Content-Length and Transfer-Encoding headers directed at FortiOS VIP-forwarded endpoints; unexpected HTTP requests appearing on backend servers that do not correspond to logged firewall traffic.
  • Logs: Discrepancies between FortiOS firewall access logs and backend server access logs — requests visible on the backend that have no corresponding entry in FortiOS logs may indicate smuggling activity.
  • Behavioral: Backend servers receiving unexpected or unauthorized HTTP requests that appear to originate from legitimate sessions; anomalous responses or errors on backend HTTP/1.1 servers not correlated with known client activity (FortiGuard Advisory).

Mitigation and workarounds

Fortinet has released patched versions to address this vulnerability. Organizations should upgrade as follows:

  • FortiOS 7.6: Upgrade to 7.6.1 or above
  • FortiOS 7.4: Upgrade to 7.4.10 or above
  • FortiOS 7.2, 7.0, 6.4: Migrate to a fixed release (no in-branch fix available)

Fortinet recommends using the official upgrade path tool at https://docs.fortinet.com/upgrade-tool. As a workaround, organizations can review and restrict firewall rules that use VIPs to forward traffic to HTTP/1.1 backend servers, as the vulnerability only affects this specific configuration (FortiGuard Advisory).

Community reactions

The Center for Internet Security (CIS) included this CVE in an advisory covering multiple Fortinet vulnerabilities (CIS Advisory). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching of affected Fortinet products. Community discussion on Reddit's r/fortinet forum addressed the vulnerability, reflecting practitioner interest in the request smuggling attack vector. The vulnerability was also flagged in the context of Siemens RUGGEDCOM APE1808 devices, which incorporate FortiOS components, broadening the affected product scope beyond standalone FortiOS deployments (BeyondMachines).

Additional resources


SourceThis report was generated using AI

Related FortiOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71407MEDIUM5.6
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesAug 12, 2026
CVE-2026-59839MEDIUM5.5
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026
CVE-2026-71408MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesAug 12, 2026
CVE-2026-70466MEDIUM5.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiweb
NoYesAug 12, 2026
CVE-2026-59840MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortiproxy
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management