CVE-2026-26365

Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-23 09:17

Updated : 2026-02-23 18:13


NVD link : CVE-2026-26365

Mitre link : CVE-2026-26365

CVE.ORG link : CVE-2026-26365


JSON object : View

Products Affected

No product.

CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')