CVE-2025-54972
An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all ve
Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
9.5th percentile
Discovered by
Not disclosed
Published
Nov 18, 2025
Assigned by fortinet
Description
An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link
Weakness: CWE-93
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiMail | Email Security | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiMail
Vendor remediation
Upgrade to upcoming FortiMail version 8.0.0 or above Upgrade to FortiMail version 7.6.4 or above Upgrade to FortiMail version 7.4.6 or above