CVE-2025-54972

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all ve

Severity
Low 3.9
CVSS 3.1
Exploited
Not listed
EPSS
0.002
9.5th percentile
Discovered by
Not disclosed
Published
Nov 18, 2025
Assigned by fortinet

Description

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Weakness: CWE-93

Affected products

Vendor Product Category Matched by
Fortinet FortiMail Email Security cna-assigner
Vendor-reported affected versions (1)
  • Fortinet · FortiMail

Vendor remediation

Upgrade to upcoming FortiMail version 8.0.0 or above Upgrade to FortiMail version 7.6.4 or above Upgrade to FortiMail version 7.4.6 or above