Fortinet white logo
Fortinet white logo

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.4.8. For inquiries about a particular bug, please contact Customer Service & Support.

Description

Bug ID

1106496 Azure deployment failed with image-definition and HyperV Gen2.
1083120, 1051968 Inline-IPS does not support FortiProxy reporting to FortiGuard for its triggered signatures.
1097304 HA goes out-of-sync repeatedly despite no configuration changes.
1109045 FPX-VM license does not change to invalid after FortiGuard server returns failure.
1108723 Certificate authentication causes redirect loop between destination URL and authentication service port 7832.
1107762 Web proxy does not respect the over-size limit value when system memory is large.
1083357, 1112229 Inline IPS does not block SharePoint upload.
1093606 Buffer overflow.

1112733

Disable warning message from nf_ct_ext_add().

1112306 Fix heap buffer overflow in HTTP request line for the CSF proxy.
1108891 Permission escalation through websocket module in Node.js granting super admin access to the CLI.
1109812 Certificate authentication scheme Issue with IP-based policy and "user-cert" option.
1045789 Dynamic address not working in transparent policy.
1113147 BUFFER_SIZE found in daemon-dnsproxy.

1111621

"Unrated" URL category object is not visible in URL category group in GUI.

1108186

"config web-proxy profile" CLI mismatch between FortiProxy and FortiManager.

1114569

L7 VIP does not work.

1103696

When the ICAP client sends a preview 0 request, the request ends with only one CRLF.

Common vulnerabilities and exposures

FortiProxy 7.4.8 is no longer vulnerable to the following CVE references. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

1147743

CVE-2025-22254

1007270 CVE-2023-46718

1112306

CVE-2025-22258

Resolved issues

Resolved issues

The following issues have been fixed in FortiProxy 7.4.8. For inquiries about a particular bug, please contact Customer Service & Support.

Description

Bug ID

1106496 Azure deployment failed with image-definition and HyperV Gen2.
1083120, 1051968 Inline-IPS does not support FortiProxy reporting to FortiGuard for its triggered signatures.
1097304 HA goes out-of-sync repeatedly despite no configuration changes.
1109045 FPX-VM license does not change to invalid after FortiGuard server returns failure.
1108723 Certificate authentication causes redirect loop between destination URL and authentication service port 7832.
1107762 Web proxy does not respect the over-size limit value when system memory is large.
1083357, 1112229 Inline IPS does not block SharePoint upload.
1093606 Buffer overflow.

1112733

Disable warning message from nf_ct_ext_add().

1112306 Fix heap buffer overflow in HTTP request line for the CSF proxy.
1108891 Permission escalation through websocket module in Node.js granting super admin access to the CLI.
1109812 Certificate authentication scheme Issue with IP-based policy and "user-cert" option.
1045789 Dynamic address not working in transparent policy.
1113147 BUFFER_SIZE found in daemon-dnsproxy.

1111621

"Unrated" URL category object is not visible in URL category group in GUI.

1108186

"config web-proxy profile" CLI mismatch between FortiProxy and FortiManager.

1114569

L7 VIP does not work.

1103696

When the ICAP client sends a preview 0 request, the request ends with only one CRLF.

Common vulnerabilities and exposures

FortiProxy 7.4.8 is no longer vulnerable to the following CVE references. Visit https://fortiguard.com/psirt for more information.

Bug ID

CVE reference

1147743

CVE-2025-22254

1007270 CVE-2023-46718

1112306

CVE-2025-22258