Akamai Rate Control Edge Hopping Rate-Limit Bypass Vulnerability
Vulnerability
A vulnerability in Akamai Rate Control alpha versions prior to 2025 allows attackers to bypass rate limits by distributing requests across different edge nodes. The rate is measured separately for each edge, enabling attackers to send a higher volume of requests than allowed by the rate limits.
Impact
Exploitation of this vulnerability allows for rate-limit bypass, enabling attackers to send requests at a high volume that exceeds the stipulated thresholds.
Remediation
Akamai has released a fix for this vulnerability, which is currently in beta mode. The release notes are available on the Akamai Tech Docs site, but access requires an Akamai account.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
