CVE-2025-54142

medium

Description

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.

References

https://www.akamai.com/blog/security-research/advisory-cve-2025-54142-http-request-smuggling-via-options-body

https://community.akamai.com/customers/s/feed/0D5a700000W51m8CAB

Details

Source: Mitre, NVD

Published: 2025-08-29

Updated: 2025-08-29

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 4

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Severity: Medium