Header injection in Web Filter warning page

Low RiskCVSS 3.4FG-IR-26-152Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

Header injection vulnerability in the web filter warning page of FortiOS and FortiProxy. An attacker can inject HTTP headers into the warning page displayed when users attempt to access blocked websites. Affected versions: FortiOS 7.6.0-7.6.4, 7.4.x, 7.2.x; FortiProxy 7.6.0-7.6.4, 7.4.x, 7.2.x. Fixed in version 7.6.5 and later for affected 7.6 releases; earlier versions require migration to a fixed release.

What this means
What could happen
An attacker could inject malicious HTTP headers into the web filter warning page, potentially redirecting users to phishing sites or injecting malicious content. This requires user interaction and affects only the warning page presented to end users, not the core security filtering function.
Who's at risk
Organizations using Fortinet FortiOS or FortiProxy as their primary web filtering gateway. This affects any network where users access blocked websites and see the warning page, including utilities with corporate office networks and operational technology boundaries that route web traffic through these devices.
How it could be exploited
An attacker crafts a specially formatted request that bypasses input validation in the web filter warning page. When a user views the warning page in response to a blocked website, the injected headers could redirect them to a malicious site or inject JavaScript into the page.
Prerequisites
  • Network access to the FortiOS or FortiProxy device on the HTTP/HTTPS ports where the web filter warning page is served
  • User must click on a blocked website and view the warning page
  • No authentication required
remotely exploitableuser interaction requiredlow complexitylow CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
FortiOS7.6.0 - 7.6.47.6.5+
FortiOS7.4 all versionsMigrate to fixed release
FortiOS7.2 all versionsMigrate to fixed release
FortiProxy7.6.0 - 7.6.47.6.5+
FortiProxy7.4 all versionsMigrate to fixed release
FortiProxy7.2 all versionsMigrate to fixed release
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

FortiOS
HOTFIXUpdate FortiOS 7.6 to version 7.6.5 or later
HOTFIXMigrate FortiOS 7.4 and 7.2 to FortiOS 7.6.5 or later
FortiProxy
HOTFIXUpdate FortiProxy 7.6 to version 7.6.5 or later
HOTFIXMigrate FortiProxy 7.4 and 7.2 to FortiProxy 7.6.5 or later
API: /api/v1/advisories/6cfcf430-ef67-4700-acf7-6ac8da4e4100

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Header injection in Web Filter warning page | CVSS 3.4 - OTPulse