ZeroHour
Fortinet PSIRTpublished ()ingested

UI DoS attack

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

FortiOS web interface is vulnerable to unauthenticated slow HTTP denial-of-service attacks via crafted requests (CVSS 5.0).

Fortinet advisory FG-IR-26-162 details an unbounded resource allocation flaw (CWE-770) in FortiOS, scored CVSSv3 5.0. An unauthenticated attacker can launch a slow HTTP denial-of-service attack against the FortiOS web interface using crafted HTTP requests. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.

  • Unbounded resource allocation (CWE-770) in the FortiOS web interface
  • Enables slow HTTP DoS via crafted requests; CVSSv3 5.0
  • Unauthenticated, remote attack surface; no exploitation reported
VendorsFortinet
ProductsFortiOS
OrganizationsFortinet
Full article

CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

This source does not provide full text. Read it at fortiguard.fortinet.com.