Executive brief
NetScaler ADC and Gateway appliances are vulnerable to a denial-of-service attack that can crash the system or disrupt network traffic. An attacker can trigger this by sending specially crafted web requests if the HTTP/2 protocol is enabled on the device. This could lead to significant downtime for applications and remote access services relying on these controllers.
Technical details
A denial-of-service vulnerability exists in NetScaler ADC and NetScaler Gateway due to improper memory management (CWE-401) when handling malformed HTTP/2 requests. The issue occurs when HTTP/2 is enabled in the HTTP Profile and associated with a virtual server (LB, CS, or VPN) or a configured service. A remote, unauthenticated attacker can exploit this by sending crafted HTTP/2 traffic, leading to resource exhaustion or service instability. Patches are available for versions 14.1 and 13.1, including FIPS-validated editions.
Affected products
- NetScaler ADC 14.1 before 72.61, 13.1 before 63.18, 14.1 FIPS before 72.61, 13.1 FIPS and NDcPP before 37.272
- NetScaler Gateway 14.1 before 72.61, 13.1 before 63.18
Timeline
- 2026-06-30: advisory: Initial disclosure by NetScaler/Citrix
- 2026-06-30: disclosed