Sceawere
Vulnerability Detail
CVE-2026-88773UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HTTP Request Smuggling in NetScaler
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 1d ago
- Vendor
- Citrix NetScaler
- Product
- ADC
- Attack Type
- CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-09-27T17:16:56.507Z",
"pubdate": "2026-09-27T17:16:56.507Z",
"executiveSummary": "This vulnerability involves an inconsistent interpretation of HTTP requests, classified as HTTP Request/Response Smuggling, affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.\nThe flaw stems from discrepancies in how the product parses and forwards HTTP traffic, potentially allowing an attacker to desynchronize the connection between the frontend proxy and the backend server.\nBy exploiting this inconsistency, a remote, unauthenticated attacker can manipulate the interpretation of subsequent requests within the same TCP stream.\nSuccessful exploitation may lead to unauthorized access to sensitive data, security control bypasses, session hijacking, or the execution of cross-site scripting (XSS) attacks by injecting content into other users' sessions.\nThe vulnerability poses a high security risk, as it allows attackers to bypass perimeter security controls and interact with internal traffic flows that the device is intended to secure.\nAffected products include NetScaler ADC and Gateway across multiple release branches (14.1 and 13.1), requiring immediate patching to the specified secure versions to mitigate the risk of exploitation.",
"technicalDetails": "The vulnerability arises from an ambiguity in how the NetScaler ADC or Gateway component handles and normalizes HTTP request headers—specifically, conflicting 'Content-Length' and 'Transfer-Encoding' header interpretations.\nWhen a frontend device (NetScaler) and a backend application server interpret the boundaries of an HTTP request differently, a request smuggling condition is established. An attacker crafts a malicious request containing both 'Content-Length' and 'Transfer-Encoding' headers, engineered to trick the NetScaler into forwarding only a portion of the request while the backend server interprets the remainder as the start of a subsequent, legitimate user's request.\nThe attack flow proceeds as follows: 1. The attacker initiates a connection to the NetScaler and sends a specially crafted, multi-part HTTP request. 2. Due to the parsing inconsistency, the NetScaler treats the initial segment of the payload as a complete request, while the backend server retains the smuggled segment in its input buffer. 3. The smuggled data remains in the buffer, prepended to the next legitimate request arriving from a different user. 4. The backend server processes the concatenated data, effectively executing the attacker's smuggled request under the context of the subsequent legitimate user's session.\nThis vulnerability is particularly critical as it does not require authentication or elevated privileges, and it can be executed over standard network exposure vectors.\nThe affected versions include ADC (before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP) and Gateway (before 14.1-73.37 FIPS and before 13.1-64.23).\nPost-exploitation impact includes the ability to bypass request-based security policies (like WAF rules), perform cache poisoning, execute unauthorized administrative actions, or exfiltrate session tokens and sensitive data from intercepted legitimate user requests. The persistence of the smuggled payload within the keep-alive connection ensures that the attacker can continuously inject content as long as the backend connection remains open."
}