VDB
CVE-2026-22153
CVE-2026-22153
PUBLISHED
CVSS 5.199999809265137 MEDIUM
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header
EPSS 0.08% · 23.2th percentile
Risk Scores
CVSS 3.1
5.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C
EPSS Score
0.08%
23.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiOS | 7.6.0, 7.4.0, 7.0.0 |
Exploit Intelligence
- https://fortiguard.fortinet.com/psirt/FG-IR-25-667 (circl)
- CIRCL seen: CVE-2025-55018 (circl-sighting)
- CIRCL seen: CVE-2025-55018 (circl-sighting)
Timeline
- Jan 6, 2026 CVE ID Reserved
- Feb 10, 2026 CVE Published
- Feb 11, 2026 EPSS Score
- Feb 11, 2026 PoC Published
- Feb 13, 2026 EPSS Score
- Feb 15, 2026 EPSS Score
- Feb 17, 2026 EPSS Score
- Feb 19, 2026 EPSS Score
- Feb 21, 2026 EPSS Score
- Feb 23, 2026 EPSS Score
- Feb 25, 2026 EPSS Score
- Feb 26, 2026 CVE Updated
References
- https://www.fortiguard.com/psirt/FG-IR-25-795 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-934 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-1052 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-384 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-093 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-661 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-528 advisory
- https://www.fortiguard.com/psirt/FG-IR-25-667 advisory
- https://fortiguard.fortinet.com/psirt/FG-IR-25-667 url