CVE-2025-5777: Citrix Bleed 2 Memory Leak Vulnerability Explained
ID: ab651977-bc03-5e3a-92cc-e6e997eafa26
STIX ID: report--ab651977-bc03-5e3a-92cc-e6e997eafa26
Feed Name: Resources-2
Threat Score
Citrix disclosed CVE-2025-5777 ("CitrixBleed 2"), a critical (CVSS 9.3) pre-authentication memory disclosure in NetScaler Gateway/AAA virtual servers that can return uninitialized stack contents inside an <initialvalue></initialvalue> XML tag when a malformed POST with an empty login parameter is submitted; the report details the vulnerability mechanics, includes an example POST request, and urges immediate patching while describing simulation and mitigation options.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
