logo

​​CVE-2025-5777: Citrix Bleed 2 Memory Leak Vulnerability Explained

ID: ab651977-bc03-5e3a-92cc-e6e997eafa26

STIX ID: report--ab651977-bc03-5e3a-92cc-e6e997eafa26

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2025-07-07

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

Citrix disclosed CVE-2025-5777 ("CitrixBleed 2"), a critical (CVSS 9.3) pre-authentication memory disclosure in NetScaler Gateway/AAA virtual servers that can return uninitialized stack contents inside an <initialvalue></initialvalue> XML tag when a malformed POST with an empty login parameter is submitted; the report details the vulnerability mechanics, includes an example POST request, and urges immediate patching while describing simulation and mitigation options.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.