PT-2025-35165 · Akamai · Akamaighost
Published
2025-08-29
·
Updated
2025-09-12
·
CVE-2025-54142
CVSS v3.1
4.0
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Akamai Ghost versions prior to 2025-07-21
Description
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body. This occurs because a subsequent request can be sent within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.
Recommendations
Update Akamai Ghost to version 2025-07-21 or later.
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Akamaighost