Description
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.

This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Published: 2026-09-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Citrix NetScaler ADC and Gateway suffer an HTTP Request/Response smuggling flaw caused by inconsistent interpretation of HTTP request headers, as identified by CWE-444. This weakness enables an attacker to craft malformed HTTP requests that are parsed differently by the load balancer and backend servers. As a result, the attacker can bypass security controls, inject malicious requests, or potentially execute arbitrary code or elevate privileges on the affected systems. The high CVSS score of 9.3 signals a severe potential impact on confidentiality, integrity, and availability.

Affected Systems

The vulnerability is present in Citrix NetScaler ADC versions prior to 14.1‑73.37, 13.1‑64.23, FIPS 14.1‑73.37, 13.1‑37.279, and NDcPP, as well as in Citrix NetScaler Gateway versions before 14.1‑73.37 FIPS and 13.1‑64.23. These affected releases feature buggy HTTP request processing that allows smuggling.

Risk and Exploitability

With a CVSS score of 9.3, the flaw poses a critical risk, but the EPSS score is not available, making the exact likelihood of exploitation unclear. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. However, the attack vector is likely remote, requiring only that an attacker can send crafted HTTP requests through the load balancer to the backend. The inconsistency in header handling provides a straightforward exploitation path for advanced adversaries.

Generated by OpenCVE AI on September 27, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Citrix NetScaler ADC and Gateway to the latest versions (14.1‑73.37 or later for ADC, 13.1‑64.23 or later for Gateway) that contain the fix for the HTTP Request/Response smuggling flaw.
  • Apply any Citrix security patch releases that address miscellaneous HTTP parsing issues for the affected NetScaler products.
  • Configure network devices or firewalls to reject HTTP/1.1 requests containing conflicting 'Content-Length' and 'Transfer-Encoding' headers, thereby mitigating smuggling as a temporary workaround.

Generated by OpenCVE AI on September 27, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Title HTTP Request Smuggling
Weaknesses CWE-444
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NetScaler

Published:

Updated: 2026-09-27T16:20:08.382Z

Reserved: 2026-09-10T07:14:57.369Z

Link: CVE-2026-88773

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T17:16:56.507

Modified: 2026-09-27T17:16:56.507

Link: CVE-2026-88773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T17:30:17Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')