Description
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.
References (2)
Core 2
Core References
Various Sources
https://community.akamai.com/customers/s/feed/0D5a700000W51m8CAB
Scores
CVSS v3
4.0
EPSS
0.0025
EPSS Percentile
15.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-444
Status
published
Products (1)
Akamai/AkamaiGhost
< 2025-07-21
Published
Aug 29, 2025
Tracked Since
Feb 18, 2026