PT-2025-32252 · Akamai · Akamaighost
Published
2025-08-07
·
Updated
2025-08-07
·
CVE-2025-32094
CVSS v3.1
4.0
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Akamai Ghost versions prior to 2025-03-26
Description
An issue exists in Akamai Ghost, used for the Akamai CDN platform. A client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can cause a discrepancy in how two in-path Akamai servers interpret the request. This allows an attacker to smuggle a second request in the original request body.
Recommendations
Update Akamai Ghost to version 2025-03-26 or later.
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Akamaighost