sk184991 - CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests

CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests

Please read this important update from Check Point.

Security Alert:

Medium

Product: Security Gateways, Spark Firewall
Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10
Last Modified: 2026-06-11

Symptoms

Gaia Portal is not affected by this issue.

Cause

An input-handling issue in the HTTP request processing path.

Solution

Mitigation

Until the fix is installed, reduce exposure to the affected HTTP service. Recommended mitigation:

  1. Limit access to Check Point web-based services (Mobile Access Portal, Identity Awareness Portals) to trusted networks only. Allow access only from administrator networks, jump servers, VPN networks, or other trusted internal networks.
  2. Block access from untrusted networks. Do not allow direct access to the affected HTTP-based service from the Internet or from networks that do not require access.
  3. Disable unused web-based services or portals. If a web-based service, portal, or feature is not required in your environment, disable it or restrict access to it according to your organization's security policy.
  4. Use an explicit Access Control rule to restrict access. Configure rules that allow only trusted source networks to reach the relevant Check Point interface or service, and drop all other access attempts.
  5. Monitor logs for unexpected HTTP access attempts. Review connections to Check Point web-based services, especially from untrusted or unexpected source addresses.

Solution

This problem was fixed. The fix strengthens HTTP request validation.

Mobile Access Portal and Identity Awareness Portals are monitored by the Check Point WatchDog service and will be automatically restarted after you install the fix.

For Security Gateways, the fix is included in:

For Spark Firewalls, see:

Article Properties

Access Level: General
Severity: Medium
Status: Approved
Date Created: 2026-05-23
Last Modified: 2026-06-11