{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-12T14:27:41.903","vulnerabilities":[{"cve":{"id":"CVE-2026-26365","sourceIdentifier":"cve@mitre.org","published":"2026-02-23T09:17:01.210","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[{"sourceIdentifier":"cve@mitre.org","tags":["exclusively-hosted-service"]}],"descriptions":[{"lang":"en","value":"Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header \"Connection: Transfer-Encoding\" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result in the origin server parsing the request body incorrectly, leading to HTTP request smuggling."},{"lang":"es","value":"Akamai Ghost en los servidores perimetrales de Akamai CDN antes del 2026-02-06 maneja incorrectamente el procesamiento de encabezados HTTP hop-by-hop personalizados, donde una solicitud entrante que contiene el encabezado 'Connection: Transfer-Encoding' podría resultar en una solicitud reenviada con un encuadre de mensaje inválido, dependiendo de la ruta de procesamiento de Akamai. Esto podría resultar en que el servidor de origen analice el cuerpo de la solicitud incorrectamente, lo que lleva al contrabando de solicitudes HTTP."}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":4.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-444"}]}],"references":[{"url":"https://www.akamai.com/blog/security-research/cve-2026-26365-incorrect-processing-connection-transfer-encoding","source":"cve@mitre.org"}]}}]}