Null Pointer Dereference in Log Report
Fortinet patched a low-severity null pointer dereference (CVSS 2.5) in FortiOS, FortiProxy, and FortiPAM that lets authenticated attackers crash the httpsd daemon.
Fortinet advisory FG-IR-26-173 describes a NULL pointer dereference vulnerability (CWE-476) in FortiOS, FortiProxy, and FortiPAM, scored CVSSv3 2.5. An authenticated attacker can crash the httpsd daemon via crafted HTTP requests, causing a denial of service. The advisory was revised on 2026-09-08.
- CVSSv3 2.5 null pointer dereference (CWE-476) in httpsd
- Affects FortiOS, FortiProxy, and FortiPAM
- Authenticated attacker can crash httpsd via crafted HTTP requests
CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.