CVE-2025-32094

MEDIUM

Akamai Ghost <2025-03-26 - SSRF

Title source: llm

Description

An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two in-path Akamai servers interpret the request, allowing an attacker to smuggle a second request in the original request body.

Exploits (1)

nomisec SCANNER 3 stars
by perplext · poc
https://github.com/perplext/echteeteepee

Scores

CVSS v3 4.0
EPSS 0.0009
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (1)
Akamai/AkamaiGhost < 2025-03-26
Published Aug 07, 2025
Tracked Since Feb 18, 2026