PT-2025-35165 · Akamai · Akamaighost

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-54142

CVSS v3.1
4.0
VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Akamai Ghost versions prior to 2025-07-21

Description:

The software contains an HTTP Request Smuggling flaw triggered by an OPTIONS request containing an entity body. This allows for the potential injection of subsequent requests within the persistent connection between an Akamai proxy server and the origin server, specifically when the origin server does not adhere to certain Internet standards.

Recommendations:

Update Akamai Ghost to version 2025-07-21 or later.

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2025-54142

Affected Products

Akamaighost