Akamai Has Addressed Browser-Powered Desync Attacks
On August 10, 2022, security researcher James Kettle presented a set of novel HTTP request smuggling attacks in his Black Hat talk, Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling.
James kindly shared the details of his work with Akamai prior to their public disclosure, and our engineering and security teams have already implemented the necessary defenses against these attacks. Today, there is no impact on the Akamai Intelligent Edge Platform. Our customers and internet users are protected.
We are grateful to James for coordinating with Akamai and making it possible to avoid any negative impact on the internet ecosystem. We also thank him for his continued contributions to the security community.