Menu

Post image 1
Post image 2
Post image 3
1 / 3
0

CVE-2025-66373: HTTP Request Smuggling Due to Invalid Chunked Body Size | Akamai

Akamai·Dec 02, 2025 Akamai·about 1 month ago
#xQMr9R7a
Reading 0:00
15s threshold

Blog Security CVE-2025-66373: HTTP Request Smuggling Due to Invalid Chunked Body Size On November 17, 2025, Akamai eliminated a potential HTTP Request Smuggling vector that resulted from incorrect processing of requests containing an invalid chunk-encoded body. Chunked transfer encoding is a data transfer mechanism available in HTTP 1.1, in which the body of an HTTP message is encoded in any number of chunks. Every chunk is made up of a chunk size followed by the chunk data of the indicated size. Akamai edge servers contained a vulnerability due to erroneous processing of requests with a chunk-encoded body. Vulnerability details Specifically, when Akamai edge servers received an invalid chunked body — one that included a chunk size that does not match the actual size of the following chunk data — the servers (under certain circumstances) incorrectly forwarded the invalid request and subsequent superfluous bytes to the origin server.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More