4.0 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @mweinelt Activity log
- Created automatic suggestion
-
@mweinelt
removed
23 packages
- ghost
- ghostie
- ghostty
- ghost-cli
- ghostfolio
- ghostunnel
- ghostscript
- ghosttohugo
- ghostty-bin
- ghostscriptX
- ghostscript_headless
- libsForQt5.ghostwriter
- kdePackages.ghostwriter
- plasma5Packages.ghostwriter
- haskellPackages.ghost-buster
- python312Packages.ghostscript
- python313Packages.ghostscript
- python314Packages.ghostscript
- tests.texlive.dvipng.ghostscript
- haskellPackages.ghostscript-parallel
- tree-sitter-grammars.tree-sitter-ghostty
- python313Packages.tree-sitter-grammars.tree-sitter-ghostty
- python314Packages.tree-sitter-grammars.tree-sitter-ghostty
- @mweinelt dismissed
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles …
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling.
Affected products
- <2026-02-06
Ignored packages (23)
pkgs.ghost
Android post-exploitation framework
-
nixos-unstable 8.0.0-unstable-2025-11-01
- nixpkgs-unstable 8.0.0-unstable-2025-11-01
- nixos-unstable-small 8.0.0-unstable-2025-11-01
pkgs.ghostie
Github notifications in your terminal
pkgs.ghostty
Fast, native, feature-rich terminal emulator pushing modern features
pkgs.ghost-cli
CLI Tool for installing & updating Ghost
pkgs.ghostfolio
Open Source Wealth Management Software
pkgs.ghostunnel
TLS proxy with mutual authentication support for securing non-TLS backend applications
pkgs.ghostscript
PostScript interpreter (mainline version)
pkgs.ghosttohugo
Convert Ghost export to Hugo posts
pkgs.ghostty-bin
Fast, native, feature-rich terminal emulator pushing modern features
pkgs.ghostscriptX
PostScript interpreter (mainline version)
pkgs.ghostscript_headless
PostScript interpreter (mainline version)
pkgs.libsForQt5.ghostwriter
Cross-platform, aesthetic, distraction-free Markdown editor
pkgs.kdePackages.ghostwriter
Text editor for Markdown
pkgs.plasma5Packages.ghostwriter
Cross-platform, aesthetic, distraction-free Markdown editor
pkgs.haskellPackages.ghost-buster
Existential type utilites
pkgs.python312Packages.ghostscript
Interface to the Ghostscript C-API using ctypes.
pkgs.python313Packages.ghostscript
Interface to the Ghostscript C-API using ctypes.
pkgs.python314Packages.ghostscript
Interface to the Ghostscript C-API using ctypes
pkgs.tests.texlive.dvipng.ghostscript
None
pkgs.haskellPackages.ghostscript-parallel
Let Ghostscript render pages in parallel
pkgs.tree-sitter-grammars.tree-sitter-ghostty
Tree-sitter grammar for ghostty
-
nixos-unstable 0-unstable-2025-11-27
- nixos-unstable-small 0-unstable-2025-11-27
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-ghostty
Python bindings for tree-sitter-ghostty
-
nixos-unstable 0+unstable20251127
- nixos-unstable-small 0+unstable20251127
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-ghostty
Python bindings for tree-sitter-ghostty
-
nixos-unstable 0+unstable20251127
- nixos-unstable-small 0+unstable20251127