VYPR

Ghost

by Akamai

CVEs (4)

  • CVE-2025-66373MedDec 4, 2025
    risk 0.31cvss 4.8epss 0.00

    Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk…

  • CVE-2026-26365MedFeb 23, 2026
    risk 0.26cvss 4.0epss 0.00

    Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the…

  • CVE-2025-54142MedAug 29, 2025
    risk 0.26cvss 4.0epss 0.00

    Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain…

  • CVE-2025-32094MedAug 7, 2025
    risk 0.26cvss 4.0epss 0.01

    An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two…