
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55018 is an HTTP Request Smuggling vulnerability (CWE-444) in Fortinet FortiOS that allows unauthenticated attackers to smuggle unlogged HTTP requests through firewall policies via a specially crafted header. The vulnerability affects FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 (all versions), FortiOS 7.0 (all versions), and FortiOS 6.4.3 through 6.4.16. It was initially published on February 10, 2026, with impact details added on February 26, 2026. The CVSS v3.1 base score is 5.8 (Medium) per NVD, while Fortinet's advisory lists a CVSSv3 score of 5.2 (Medium) (FortiGuard Advisory).
The vulnerability is classified as CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling), where FortiOS inconsistently parses HTTP request headers, enabling an attacker to craft requests that are interpreted differently by the FortiOS firewall and the backend HTTP/1.1 server. Exploitation requires that firewall rules use a Virtual IP (VIP) to forward requests to an HTTP/1.1 backend server — this is a key precondition. By sending a specially crafted HTTP header, an unauthenticated remote attacker can cause a secondary, unlogged HTTP request to be forwarded through firewall policies, effectively bypassing inspection and logging. The vulnerability was discovered internally by Daobing Li from the Fortinet R&D Team (FortiGuard Advisory).
Successful exploitation allows an unauthenticated attacker to smuggle HTTP requests through FortiOS firewall policies without those requests being logged, enabling policy evasion and integrity compromise. The primary impact is on integrity (low) with a changed scope, meaning the attacker can influence resources beyond the vulnerable component itself — specifically, backend servers protected by the firewall. There is no direct confidentiality or availability impact, but the ability to bypass firewall inspection and logging undermines security monitoring and could facilitate further attacks against backend systems that rely on the firewall for protection (FortiGuard Advisory, Feedly).
As of the advisory date, Fortinet has confirmed this vulnerability is not known to be exploited in the wild (FortiGuard Advisory). The EPSS score is approximately 0.031% (0.000310), indicating a low probability of exploitation in the near term. No public proof-of-concept exploit code or threat actor attribution has been identified. The vulnerability is detectable via Qualys scanner (detection ID 591683) and Tenable Nessus (plugin 298523). The attack requires no authentication and no user interaction, but is limited to environments where VIP-based HTTP/1.1 forwarding rules are configured.
Content-Length and Transfer-Encoding headers, or malformed chunked encoding) designed to be interpreted differently by FortiOS and the backend server.Content-Length and Transfer-Encoding headers directed at FortiOS VIP-forwarded endpoints; unexpected HTTP requests appearing on backend servers that do not correspond to logged firewall traffic.Fortinet has released patched versions to address this vulnerability. Organizations should upgrade as follows:
Fortinet recommends using the official upgrade path tool at https://docs.fortinet.com/upgrade-tool. As a workaround, organizations can review and restrict firewall rules that use VIPs to forward traffic to HTTP/1.1 backend servers, as the vulnerability only affects this specific configuration (FortiGuard Advisory).
The Center for Internet Security (CIS) included this CVE in an advisory covering multiple Fortinet vulnerabilities (CIS Advisory). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching of affected Fortinet products. Community discussion on Reddit's r/fortinet forum addressed the vulnerability, reflecting practitioner interest in the request smuggling attack vector. The vulnerability was also flagged in the context of Siemens RUGGEDCOM APE1808 devices, which incorporate FortiOS components, broadening the affected product scope beyond standalone FortiOS deployments (BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."