Description
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Published: 2026-06-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malformed HTTP/2 request can trigger a denial-of-service condition in Citrix NetScaler ADC and NetScaler Gateway appliances when HTTP/2 is enabled in an HTTP Profile linked to a virtual server or service. The flaw causes the device to consume excessive resources and become unresponsive to legitimate traffic, effectively taking the managed services offline. This is a classic memory exhaustion or resource depletion weakness (CWE‑401).

Affected Systems

Citrix NetScaler ADC and NetScaler Gateway appliances that have HTTP/2 enabled in an HTTP Profile associated with a virtual server of type Load Balancing, Content Switching, or VPN, or with a service configured on NetScaler. No specific vendor version is listed, so the issue applies to all affected product editions that permit the configuration in question.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score is not available, so the exploitation probability cannot be quantified. The flaw is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The likely attack vector is remote, where an adversary sends specially crafted HTTP/2 traffic to the exposed NetScaler interfaces. Successful exploitation would result in denial of service for legitimate users and potentially disrupt business availability.

Generated by OpenCVE AI on June 30, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Citrix patch described in article CTX696604 to correct HTTP/2 request handling on NetScaler ADC and NetScaler Gateway.
  • If the patch cannot be applied immediately, disable HTTP/2 in every HTTP profile linked to vulnerable virtual servers or services to prevent the exploit.
  • Configure monitoring of system logs and traffic for repeated malformed HTTP/2 requests, and apply rate limiting or blocking rules on affected virtual servers.
  • Optionally, configure firewall or ACL rules to restrict HTTP/2 traffic to trusted networks or IP ranges.

Generated by OpenCVE AI on June 30, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Netscaler
Netscaler adc
Netscaler gateway
Vendors & Products Netscaler
Netscaler adc
Netscaler gateway

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Title Denial of service via malformed HTTP/2 requests
Weaknesses CWE-401
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-06-30T13:27:27.938Z

Reserved: 2026-06-26T22:24:26.657Z

Link: CVE-2026-13474

cve-icon Vulnrichment

Updated: 2026-06-30T13:27:22.904Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T18:00:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime