Akamai acquires LayerX, delivering end-to-end security and real-time AI usage control to any browser. Get details

CVE-2025-66373: HTTP Request Smuggling Due to Invalid Chunked Body Size

Akamai Wave Blue

Dec 02, 2025

Akamai

Akamai Wave Blue

Written by

Akamai

Share

On November 17, 2025, Akamai eliminated a potential HTTP Request Smuggling vector that resulted from incorrect processing of requests containing an invalid chunk-encoded body.

Chunked transfer encoding is a data transfer mechanism available in HTTP 1.1, in which the body of an HTTP message is encoded in any number of chunks. Every chunk is made up of a chunk size followed by the chunk data of the indicated size.

Akamai edge servers contained a vulnerability due to erroneous processing of requests with a chunk-encoded body.

Vulnerability details

Specifically, when Akamai edge servers received an invalid chunked body — one that included a chunk size that does not match the actual size of the following chunk data — the servers (under certain circumstances) incorrectly forwarded the invalid request and subsequent superfluous bytes to the origin server.

An attacker could have hidden a smuggled request in these superfluous bytes, exposing Akamai customers to potential HTTP Request Smuggling attacks. Whether this vulnerability was exploitable in practice depended on the origin server’s behavior and how it processed the invalid request it received from Akamai.

Mitigation

Akamai became aware of this issue on September 18, 2025. On November 17, 2025, a full fix was deployed, completely eliminating the vulnerability from all Akamai services. No remediation action is required by customers.

As part of our regular incident response work and vulnerability analysis, we have disclosed this issue through CVE-2025-66373.

Special thanks

We thank “Jinone (@jinonehk)” for reporting the findings that led to the discovery of this issue through Akamai’s Bug Bounty Program, and coordinating with us throughout our investigation, which helped make the internet more secure.

Akamai Wave Blue

Dec 02, 2025

Akamai

Akamai Wave Blue

Written by

Akamai

Tags

Share

Related Blog Posts

Security
OMB M-26-14 Compliance: Adaptive Edge Logging for Federal CISOs
August 04, 2026
Achieve OMB M-26-14 compliance despite FY27 budget cuts. Learn how Akamai edge-driven architectures optimize CEM, THIRF, and Zero Trust visibility.
Security
Akamai Mitigates Record DDoS Attack in Asia-Pacific (900 Gbps)
March 08, 2023
Akamai mitigated the largest DDoS attack that it's ever seen in Asia-Pacific, with attack traffic peaking at 900.1 gigabytes per second.
Security
OWASP Top 10 API Security Risks: The 2023 Edition Is Finally Here
June 21, 2023
We review the final changes in the 2023 update to the OWASP Top 10 API Security Risks to help you on your journey to secure your APIs.