CVE-2025-54972

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all ve

Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
10.2th percentile
Discovered by
Vendor
Vendor advisory field
Published
Nov 18, 2025
Assigned by fortinet

Description

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Weakness: CWE-93

Affected products

Vendor Product Category Matched by
Fortinet FortiMail Email Security cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiMail

Credit

Internally discovered and reported by Jaguar Perlas from Fortinet Infosec team

Vendor remediation

Upgrade to upcoming FortiMail version 8.0.0 or above Upgrade to FortiMail version 7.6.4 or above Upgrade to FortiMail version 7.4.6 or above

Something wrong here?