Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-88773",
"assignerOrgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"assignerShortName": "NetScaler",
"dateUpdated": "2026-09-27T16:20:08.382Z",
"dateReserved": "2026-09-10T07:14:57.369Z",
"datePublished": "2026-09-27T16:20:08.382Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "50a63c94-1ea7-4568-8c11-eb79e7c5a2b5",
"shortName": "NetScaler",
"dateUpdated": "2026-09-27T16:20:08.382Z"
},
"datePublic": "2026-09-27T15:30:00.000Z",
"title": "HTTP Request Smuggling",
"descriptions": [
{
"lang": "en",
"value": "Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.\n\nThis issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.<p>This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.</p>"
}
]
}
],
"affected": [
{
"vendor": "Citrix NetScaler",
"product": "ADC",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "14.1-73.37"
},
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "13.1-64.23"
},
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "14.1-73.37 FIPS"
},
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "13.1-37.279 and NDcPP"
}
]
},
{
"vendor": "Citrix NetScaler",
"product": "Gateway",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "14.1-73.37 FIPS"
},
{
"version": "0",
"status": "affected",
"versionType": "Patch",
"lessThan": "13.1-64.23"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-444 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling')",
"cweId": "CWE-444",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
]
}
}
}