CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-88773

CVE-2026-88773: Critical HTTP Request Smuggling in Citrix NetScaler ADC and Gateway

Amit Schendel
Amit Schendel
Senior Security Researcher

Sep 29, 2026·6 min read·3 visits

Executive Summary (TL;DR)

Unauthenticated HTTP request smuggling in Citrix NetScaler allows session hijacking, policy bypass, and cache poisoning due to boundary parsing differences.

A critical HTTP request/response smuggling vulnerability (CWE-444) exists in Citrix NetScaler ADC and Citrix NetScaler Gateway. This flaw arises from inconsistent request boundary parsing between NetScaler appliances and backend web servers, allowing remote, unauthenticated attackers to bypass security boundaries, access restricted resources, or hijack active user sessions on multiplexed TCP connections.

Vulnerability Overview

CVE-2026-88773 is a critical HTTP request/response smuggling vulnerability (CWE-444) affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. This vulnerability was disclosed on September 27, 2026, as part of Citrix Security Bulletin CTX697096. The vulnerability occurs due to inconsistencies in how HTTP requests are sanitized, parsed, and forwarded to backend servers.

The NetScaler appliance serves as a front-end reverse proxy or load balancer, managing multiplexed TCP connections to downstream web applications. By design, NetScaler reuses downstream persistent connections for multiple incoming user sessions to optimize performance. This architecture introduces a significant attack surface if request boundaries are processed inconsistently.

An unauthenticated remote attacker can exploit this issue by crafting malformed HTTP requests containing conflicting boundary indicators. When these requests are routed, the downstream backend server retains the smuggled payload in its buffer. This payload is subsequently prepended to the next legitimate user's request, resulting in session hijack or security policy bypass.

Root Cause Analysis

The underlying flaw stems from inconsistent interpretation of HTTP requests (CWE-444) between NetScaler and backend web servers. When processing HTTP/1.1 message bodies, servers determine request boundaries using either the Content-Length header or the Transfer-Encoding: chunked header. A discrepancy occurs if the proxy and the backend prioritize these headers differently or disagree on malformed header syntax.

For instance, if the proxy processes a request based on Content-Length but the backend processes it based on Transfer-Encoding, the backend parses a different portion of the HTTP body as the completion of the request. The trailing bytes of the attacker's request are then treated as the start of a subsequent HTTP request.

This behavior is highly exploitable because NetScaler implements TCP connection multiplexing. To reduce the overhead of initiating three-way handshakes with backend servers, NetScaler maintains persistent TCP pools. Because multiple client sessions share the same downstream TCP socket, an attacker can reliably prefix a smuggled payload onto the request stream of an unrelated, legitimate user.

Technical Flow and Boundary Discrepancies

The request smuggling mechanism relies on synchronization loss between the proxy's outgoing stream and the backend's incoming parser. The diagram below illustrates the flow of the attack when a shared TCP socket is used to multiplex incoming user connections.

In this scenario, the NetScaler and the backend server process different boundaries. The backend server holds the remainder of the attacker's data in its stream buffer. When the legitimate user's request is multiplexed over the same TCP connection, the backend appends the user's headers to the smuggled payload, executing the smuggled action.

Exploitation and Request Construction

Exploitation requires no authentication and can be completed via direct HTTP requests. In a Content-Length vs. Transfer-Encoding (CL.TE) scenario, the attacker issues a single POST request containing both headers. NetScaler prioritizes Content-Length while the backend prioritizes Transfer-Encoding.

POST / HTTP/1.1
Host: target.example.com
Content-Length: 4
Transfer-Encoding: chunked
 
1
Z
0
 
GET /admin/delete_user?id=99 HTTP/1.1
Host: target.example.com
Dummy: 

In this packet payload, the NetScaler reads the Content-Length: 4 and forwards only the first 4 bytes of the body (up to 1\r\nZ\r\n) to the backend. The backend, reading the request as chunked, identifies the 0 chunk as the message terminator and parses the remaining GET request as the beginning of the subsequent request. When a legitimate user's request arrives, it is appended to the Dummy: header, making the entire operation execute under the user's session context.

Impact Assessment and Vulnerability Scope

The impact of CVE-2026-88773 is rated as critical, with a CVSS v3.1 base score of 10.0 and a CVSS v4.0 score of 9.3. Successful exploitation allows complete security boundary bypass. If the front-end NetScaler is configured to perform authorization checks, an attacker can bypass these completely by smuggling requests to backend components that trust the NetScaler's upstream validation.

Type-specific session hijacking is achievable without user interaction. When a legitimate user's request is appended to the smuggled payload, the user's cookie headers are often forwarded as query parameters or headers in the smuggled request, exposing them to the attacker via log files or application responses.

Local web cache poisoning is another significant threat. Attackers can smuggle a request that maps a legitimate static resource to a malicious page. If NetScaler or an intermediate cache stores this combined response, subsequent users requesting the legitimate page will receive the malicious payload.

Audit and Exposure Verification

An appliance is vulnerable only if it is configured to run active virtual servers handling HTTP or SSL traffic. Administrators must audit configuration files to assess exposure. This requires searching both the default partition and all active admin partitions for virtual servers using vulnerable protocols.

Administrators can inspect the /nsconfig/ns.conf file directly using the command line shell. The following command pattern identifies exposed configurations:

grep -iE -e "^add (lb|cs|vpn|authentication) vserver ("[^"]*"|[^ ]+) (HTTP|SSL) " /nsconfig/ns.conf

If the command returns output lines and the appliance is running an affected firmware version, the system is exposed. For systems utilizing administrative partitions, configurations under /nsconfig/partitions/*/ns.conf must also be searched recursively to ensure complete audit coverage.

Remediation and Mitigation Strategies

To remediate CVE-2026-88773, administrators must upgrade to fixed releases of NetScaler ADC and Gateway. For 14.1 deployments, upgrade to 14.1-73.37 or later. For 13.1 deployments, upgrade to 13.1-64.24 or later (this version avoids a known cyclic-reboot issue present in build 13.1-64.23).

If immediate upgrading is impossible, temporary workarounds include disabling connection multiplexing on HTTP profiles or configuring strict header checking on downstream web servers. However, these changes may degrade performance or disrupt application functionality.

As part of general gateway hardening, Citrix also recommends enabling Enhanced ISN Generation on all active partitions. This parameter mitigates TCP sequence prediction risks (CVE-2026-88778) and can be enabled via CLI using set ns tcpparam -enhancedISNgeneration ENABLED.

Technical Appendix

CVSS Score
10.0/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
15,000
via Shodan

Affected Systems

Citrix NetScaler ADC (Standard/Enterprise/Platinum)Citrix NetScaler GatewayCitrix NetScaler ADC FIPSCitrix NetScaler ADC NDcPP
AttributeDetail
CWE IDCWE-444
Attack VectorNetwork (AV:N)
CVSS v3.1 Score10.0 (Critical)
CVSS v4.0 Score9.3 (Critical)
Exploit StatusNone/Theoretical (No public PoC code)
CISA KEV StatusNot Listed (Related CVEs CVE-2026-88771/2 are listed)
Primary ImpactSession Hijacking, Security Bypass, Cache Poisoning
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Vulnerability Timeline

Citrix Security Bulletin CTX697096 Published and CVE-2026-88773 Disclosed
2026-09-27
CISA Alert issued for adjacent zero-day vulnerabilities in the same bulletin
2026-09-27
Community release of netscaler-ctx697096-checker audit script
2026-09-28

More Reports

•22 minutes ago•CVE-2026-92905
5.3

CVE-2026-92905: Denial of Service in Zoho ManageEngine EventLog Analyzer and Log360 Log Collector

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a denial-of-service (DoS) vulnerability that allowed unauthenticated remote attackers to crash the log collector service using malformed syslog packets.

Alon Barad
Alon Barad
4 views•5 min read
•about 1 hour ago•CVE-2026-88058
8.6

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

Alon Barad
Alon Barad
4 views•9 min read
•about 2 hours ago•CVE-2026-101910
6.9

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

A validation bypass vulnerability exists in the npm package `ip-address` from version 10.2.0 to 10.5.1. The library's `Address6.isPrivate()` classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

Alon Barad
Alon Barad
4 views•6 min read
•about 3 hours ago•CVE-2026-101913
6.3

CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF

A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.

Alon Barad
Alon Barad
4 views•6 min read
•about 4 hours ago•CVE-2026-84394
7.5

CVE-2026-84394: Host Confusion and SSRF Bypass via Parser Discrepancy in fast-uri

An interpretation conflict in the fast-uri library allows unauthenticated remote attackers to bypass Server-Side Request Forgery filters due to inconsistent handling of malformed bracket notation in hostnames.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-84292
7.5

CVE-2026-84292: Authority Injection in fast-uri via Unvalidated Port Component

An authority injection vulnerability exists in the serialization components of fast-uri (versions before 2.4.6, 3.1.7, and 4.1.4) where unvalidated port components can contain authority delimiters (such as '@'). This results in host demotion to userinfo, redirection of traffic to an arbitrary attacker-controlled host, and downstream Server-Side Request Forgery (SSRF) without causing parser errors in standard clients.

Amit Schendel
Amit Schendel
6 views•7 min read