> Source: [sk184991](https://support.checkpoint.com/results/sk/sk184991)

# sk184991 - CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests

| Property | Value |
|----------|-------|
| Solution ID | sk184991 |
| Date Created | 2026-05-23 |
| Last Modified | 2026-06-11 |
| Technical Level | General |
| Products | Security Gateway, Spark Firewall (Locally Managed) |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.00.X, R81.10.X, R81 (EOS) |

## Symptoms

- * A Check Point HTTP-based service, such as Mobile Access Portal or Identity Awareness Portals (except for Captive Portal), can incorrectly handle malformed HTTP requests.  
  Gaia Portal is not affected by this issue.
* The issue is related to HTTP request parsing and validation.
* The attacker can exploit this vulnerability leading to Denial of Service, HTTP header injection, or heap buffer overflow.
* This issue affects:  
  * R82.10 with Jumbo Hotfix Take 6 or below
  * R82 with Jumbo Hotfix Take 91 or below
  * R81.20 with Jumbo Hotfix Take 127 or below
  * All releases from R81.10 and below
* This issue received the ID [CVE-2026-48135](https://www.cve.org/CVERecord?id=CVE-2026-48135).

## Cause

An input-handling issue in the HTTP request processing path.

## Solution

### Mitigation

Until the fix is installed, reduce exposure to the affected HTTP service. Recommended mitigation:

1. Limit access to Check Point web-based services (Mobile Access Portal, Identity Awareness Portals) to trusted networks only. Allow access only from administrator networks, jump servers, VPN networks, or other trusted internal networks.
2. Block access from untrusted networks. Do not allow direct access to the affected HTTP-based service from the Internet or from networks that do not require access.
3. Disable unused web-based services or portals. If a web-based service, portal, or feature is not required in your environment, disable it or restrict access to it according to your organization's security policy.
4. Use an explicit Access Control rule to restrict access. Configure rules that allow only trusted source networks to reach the relevant Check Point interface or service, and drop all other access attempts.
5. Monitor logs for unexpected HTTP access attempts. Review connections to Check Point web-based services, especially from untrusted or unexpected source addresses.

### Solution

This problem was fixed. The fix strengthens HTTP request validation.  

Mobile Access Portal and Identity Awareness Portals are monitored by the Check Point WatchDog service and will be automatically restarted after you install the fix.  

For Security Gateways, the fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 141
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 187

<br />

For Spark Firewalls, see:

* R81.10.17 -**[sk183153](https://support.checkpoint.com/results/sk/sk183153)**
* R82.00.10 -**[sk184357](https://support.checkpoint.com/results/sk/sk183157)**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
