PoC Archive PoC Archive

tag

Gateway

  • CVE-2026-8452 network CRITICAL 9.8

    Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)

    CVE-2026-8452 is a pre-authentication heap buffer overflow in the Citrix NetScaler ADC and Gateway SAML authentication handler. The vulnerability exists in the XML Signature Canonicalization (C14N) processing of the PrefixList attribute within SAML responses.…

    Patched 2026-08-16
  • CVE-2026-28466 network CRITICAL

    OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466

    OpenClaw exposes a WebSocket control-plane gateway (/ws) used to manage connected nodes/agents. The gateway's connect handshake accepts a client-supplied auth token and role/scope set without properly validating that the presented token is bound to the…

    Patched 2026-07-05
  • CVE-2026-8451 network HIGH 7.5 EPSS 16%

    Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451)

    CVE-2026-8451 is a pre-authentication out-of-bounds memory read in Citrix NetScaler ADC/Gateway's SAML request parser, in the same vulnerability class as the infamous 2023 "CitrixBleed" (CVE-2023-4966). By posting a specially-sized, malformed SAMLRequest to…

    Unverified 2026-07-03
  • CVE-2025-5777 web CRITICAL 9.3 KEV Ransomware EPSS 100%

    Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)

    CVE-2025-5777 ("CitrixBleed 2") is an unauthenticated out-of-bounds memory disclosure in Citrix NetScaler ADC/Gateway authentication processing. A crafted request can leak chunks of process memory that may contain active session tokens and credentials.…

    Patched 2026-05-16