CVE Vulnerabilities

CVE-2025-54972

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Nov 18, 2025 | Modified: Jan 14, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper neutralization of crlf sequences (crlf injection) vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
FortimailFortinet7.0.0 (including)7.4.6 (excluding)
FortimailFortinet7.6.0 (including)7.6.4 (excluding)

Potential Mitigations

References