Akamai acquires LayerX, delivering end-to-end security and real-time AI usage control to any browser. Get details

CVE-2025-66373: HTTP Request Smuggling Due to Invalid Chunked Body Size

Akamai Wave Blue

Dec 02, 2025

Akamai

Akamai Wave Blue

Written by

Akamai

Share

On November 17, 2025, Akamai eliminated a potential HTTP Request Smuggling vector that resulted from incorrect processing of requests containing an invalid chunk-encoded body.

Chunked transfer encoding is a data transfer mechanism available in HTTP 1.1, in which the body of an HTTP message is encoded in any number of chunks. Every chunk is made up of a chunk size followed by the chunk data of the indicated size.

Akamai edge servers contained a vulnerability due to erroneous processing of requests with a chunk-encoded body.

Vulnerability details

Specifically, when Akamai edge servers received an invalid chunked body — one that included a chunk size that does not match the actual size of the following chunk data — the servers (under certain circumstances) incorrectly forwarded the invalid request and subsequent superfluous bytes to the origin server.

An attacker could have hidden a smuggled request in these superfluous bytes, exposing Akamai customers to potential HTTP Request Smuggling attacks. Whether this vulnerability was exploitable in practice depended on the origin server’s behavior and how it processed the invalid request it received from Akamai.

Mitigation

Akamai became aware of this issue on September 18, 2025. On November 17, 2025, a full fix was deployed, completely eliminating the vulnerability from all Akamai services. No remediation action is required by customers.

As part of our regular incident response work and vulnerability analysis, we have disclosed this issue through CVE-2025-66373.

Special thanks

We thank “Jinone (@jinonehk)” for reporting the findings that led to the discovery of this issue through Akamai’s Bug Bounty Program, and coordinating with us throughout our investigation, which helped make the internet more secure.

Akamai Wave Blue

Dec 02, 2025

Akamai

Akamai Wave Blue

Written by

Akamai

Tags

Share

Related Blog Posts

Security
Akamai Blog | Adding Multi-Factor Authentication to Employee Logins: A Sound Security Principle
February 22, 2022
The year 2021 was definitely challenging for security practitioners. The number of data breaches continued to rise; a report issued by the Identity Theft Resource Center stated that the total number of breaches in the first three quarters of 2021 exceeded the total number of events in all of 2020 by 17%.
Security
Akamai Blog | Why FIDO2 is the Answer to Better Security
May 21, 2021
A groundbreaking increase in security incidents is affecting governments around the world. In light of this, the United States issued a formal order to implement a robust set of security measures designed to improve the security of federal systems. In his most recent executive order, President Biden acknowledged that the United States and many other governments around the world are facing increasing malicious cyberattacks. In order to prevent, and recover from security incidents, the President is pushing to significantly improve the government's security stack, including the implementation of multi-factor authentication (MFA). In this post, I'll discuss how the government's plan to leverage MFA could be even better.
Security
PQC Migration Now Has a Deadline. Does Your DNS Estate?
July 23, 2026
Learn why crypto-agility depends not just on adopting the right standards, but on maintaining a clear, unified view of your DNS environment before the migration begins.