PT-2026-21505 · Akamai · Akamai
Publicado
2026-02-23
·
Atualizado
2026-02-23
·
CVE-2026-26365
CVSS v3.1
4.0
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Akamai versions prior to 2026-02-06
Description
The software mishandles processing of custom hop-by-hop HTTP headers. An incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could lead to HTTP request smuggling, potentially causing the origin server to parse the request body incorrectly.
Recommendations
Update to a version released on or after 2026-02-06.
Correção
HTTP Request/Response Smuggling
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Akamai