Home

Description

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.

PUBLISHED Reserved 2025-07-17 | Published 2025-08-29 | Updated 2025-08-29 | Assigner mitre




MEDIUM: 4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Problem types

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Product status

Default status
unaffected

Any version before 2025-07-21
affected

References

community.akamai.com/customers/s/feed/0D5a700000W51m8CAB

www.akamai.com/...42-http-request-smuggling-via-options-body

cve.org (CVE-2025-54142)

nvd.nist.gov (CVE-2025-54142)

Download JSON