10

CVE-2026-88773

Warnung

HTTP Request Smuggling

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Netscaler Application Delivery Controller SwEdition - Version >= 13.1 < 13.1-64.23
Citrix ≫ Netscaler Application Delivery Controller SwEdition fips Version >= 13.1 < 13.1.37.279
Citrix ≫ Netscaler Application Delivery Controller SwEdition ndcpp Version >= 13.1 < 13.1.37.279
Citrix ≫ Netscaler Application Delivery Controller SwEdition - Version >= 14.1 < 14.1-73.37
Citrix ≫ Netscaler Application Delivery Controller SwEdition fips Version >= 14.1-66.68 <= 14.1-73.37
Citrix ≫ NetScaler Gateway Version >= 13.1 < 13.1-64.23
Citrix ≫ NetScaler Gateway Version >= 14.1 < 14.1-73.37
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.274
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Vendor Advisory