CVE-2025-66373 Details
Description
Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk data, under certain circumstances, Akamai Ghost erroneously forwards the invalid request and subsequent superfluous bytes to the origin server. An attacker could hide a smuggled request in these superfluous bytes. Whether this is exploitable depends on the origin server's behavior and how it processes the invalid request it receives from Akamai Ghost.
Akamai Ghost running on Akamai CDN edge servers prior to 2025-11-17 contains a vulnerability that allows HTTP request smuggling due to improper handling of chunked request bodies. When an invalid chunked body is received—specifically one where the chunk size does not match the actual data size—Akamai Ghost may incorrectly forward the flawed request along with extra bytes to the origin server. This creates an opportunity for an attacker to conceal a smuggled request within these additional bytes. The exploitability of this vulnerability depends on how the origin server reacts to the received invalid request.
Akamai has deployed a fix for this vulnerability on 2025-11-17. No action is required by customers.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en.wikipedia.org/wiki/HTTP_request_smuggling | [email protected] | Technical Description |
| https://www.akamai.com/blog/security/cve-2025-66373-http-request-smuggling-chunked-body-size | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| akamai akamaighost | < 2025-11-17 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 16, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | CVE Modified | CISA-ADP |
| Dec 4, 2025 | New CVE Received | [email protected] |