Sceawere

Vulnerability Detail

CVE-2026-88773UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HTTP Request Smuggling in NetScaler

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
1d ago
Vendor
Citrix NetScaler
Product
ADC
Attack Type
CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-09-27T17:16:56.507Z",
  "pubdate": "2026-09-27T17:16:56.507Z",
  "executiveSummary": "This vulnerability involves an inconsistent interpretation of HTTP requests, classified as HTTP Request/Response Smuggling, affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.\nThe flaw stems from discrepancies in how the product parses and forwards HTTP traffic, potentially allowing an attacker to desynchronize the connection between the frontend proxy and the backend server.\nBy exploiting this inconsistency, a remote, unauthenticated attacker can manipulate the interpretation of subsequent requests within the same TCP stream.\nSuccessful exploitation may lead to unauthorized access to sensitive data, security control bypasses, session hijacking, or the execution of cross-site scripting (XSS) attacks by injecting content into other users' sessions.\nThe vulnerability poses a high security risk, as it allows attackers to bypass perimeter security controls and interact with internal traffic flows that the device is intended to secure.\nAffected products include NetScaler ADC and Gateway across multiple release branches (14.1 and 13.1), requiring immediate patching to the specified secure versions to mitigate the risk of exploitation.",
  "technicalDetails": "The vulnerability arises from an ambiguity in how the NetScaler ADC or Gateway component handles and normalizes HTTP request headers—specifically, conflicting 'Content-Length' and 'Transfer-Encoding' header interpretations.\nWhen a frontend device (NetScaler) and a backend application server interpret the boundaries of an HTTP request differently, a request smuggling condition is established. An attacker crafts a malicious request containing both 'Content-Length' and 'Transfer-Encoding' headers, engineered to trick the NetScaler into forwarding only a portion of the request while the backend server interprets the remainder as the start of a subsequent, legitimate user's request.\nThe attack flow proceeds as follows: 1. The attacker initiates a connection to the NetScaler and sends a specially crafted, multi-part HTTP request. 2. Due to the parsing inconsistency, the NetScaler treats the initial segment of the payload as a complete request, while the backend server retains the smuggled segment in its input buffer. 3. The smuggled data remains in the buffer, prepended to the next legitimate request arriving from a different user. 4. The backend server processes the concatenated data, effectively executing the attacker's smuggled request under the context of the subsequent legitimate user's session.\nThis vulnerability is particularly critical as it does not require authentication or elevated privileges, and it can be executed over standard network exposure vectors.\nThe affected versions include ADC (before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP) and Gateway (before 14.1-73.37 FIPS and before 13.1-64.23).\nPost-exploitation impact includes the ability to bypass request-based security policies (like WAF rules), perform cache poisoning, execute unauthorized administrative actions, or exfiltrate session tokens and sensitive data from intercepted legitimate user requests. The persistence of the smuggled payload within the keep-alive connection ensures that the attacker can continuously inject content as long as the backend connection remains open."
}
CVE-2026-88773: HTTP Request Smuggling in NetScaler (CRITICAL Severity, CVSS: 10.0) | Sceawere