CVE-2026-13474
EUVD-2026-4032030.06.2026, 13:17
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScalerEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| citrix | netscaler_application_delivery_controller | 𝑥 < 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | 𝑥 < 13.1-37.272 |
| citrix | netscaler_application_delivery_controller | 13.1 ≤ 𝑥 < 13.1-63.18 |
| citrix | netscaler_application_delivery_controller | 14.1 ≤ 𝑥 < 14.1-72.61 |
| citrix | netscaler_application_delivery_controller | 14.1-66.68 |
| citrix | netscaler_gateway | 13.1 ≤ 𝑥 < 13.1-63.18 |
| citrix | netscaler_gateway | 14.1 ≤ 𝑥 < 14.1-72.61 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration