ZeroHour
Fortinet PSIRTpublished ()ingested

Content-Encoding WAF Evasion

lowAdvisoryimportance 22
AI summary · glm-5.3-flash

FortiWeb WAF policies can be bypassed by unauthenticated attackers using crafted Content-Encoding requests (CVSS 4.8).

Fortinet disclosed an incomplete list of disallowed inputs (CWE-184) in FortiWeb's WAF, tracked as FG-IR-26-157. An unauthenticated attacker can bypass WAF policies using specifically crafted requests with crafted Content-Encoding values. The issue carries a CVSSv3 score of 4.8 and was revised on 2026-08-12. The advisory does not report active exploitation.

  • Incomplete input filtering (CWE-184) allows unauthenticated WAF policy bypass
  • Crafted Content-Encoding requests evade the FortiWeb disallowed-input list
  • CVSSv3 4.8; no exploitation reported in the advisory
ProductsFortiWeb
OrganizationsFortinet
Full article

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.