CVE-2025-66378: High severity Pexip Infinity vulnerability
Published Dec 25, 2025
·Updated
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
Affected Software
2 affected components
Pexip Infinity>38.0<=38.1
Pexip Pexip Infinity>=38.0<39.0
Event History
Dec 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66378?
The CVE-2025-66378 vulnerability is considered a medium severity due to its potential impact on RTMP stream stability.
2
How do I fix CVE-2025-66378?
To fix CVE-2025-66378, update Pexip Infinity to version 39.0 or later, which includes the necessary access control improvements.
3
What systems are affected by CVE-2025-66378?
CVE-2025-66378 affects Pexip Infinity versions 38.0 and 38.1.
4
What type of attack can CVE-2025-66378 enable?
CVE-2025-66378 allows an attacker to disconnect RTMP streams traversing a Proxy Node, disrupting the streaming service.
5
What should administrators know about CVE-2025-66378?
Administrators should be aware of the insufficient access control in RTMP implementation and prioritize upgrading to mitigate potential disruptions.