UI DoS attack
FortiOS web interface is vulnerable to unauthenticated slow HTTP denial-of-service attacks via crafted requests (CVSS 5.0).
Fortinet advisory FG-IR-26-162 details an unbounded resource allocation flaw (CWE-770) in FortiOS, scored CVSSv3 5.0. An unauthenticated attacker can launch a slow HTTP denial-of-service attack against the FortiOS web interface using crafted HTTP requests. The advisory was revised on 2026-08-12 and does not state that exploitation has been observed.
- Unbounded resource allocation (CWE-770) in the FortiOS web interface
- Enables slow HTTP DoS via crafted requests; CVSSv3 5.0
- Unauthenticated, remote attack surface; no exploitation reported
CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00
This source does not provide full text. Read it at fortiguard.fortinet.com.