30
30
Content-Encoding WAF Evasion
FortiWeb WAF policies can be bypassed by unauthenticated attackers using crafted Content-Encoding requests (CVSS 4.8).
Fortinet disclosed an incomplete list of disallowed inputs (CWE-184) in FortiWeb's WAF, tracked as FG-IR-26-157. An unauthenticated attacker can bypass WAF policies using specifically crafted requests with crafted Content-Encoding values. The issue carries a CVSSv3 score of 4.8 and was revised on 2026-08-12. The advisory does not report active exploitation.
22
45
30
45
30
30
30
30
30
30
30
30
30
45
45
30
30
30
30
45
30
30
30
45
45
30
30
30
30
30
30
30
30
30
30
30
30