Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/0xblackash/cve-2026-8451
Memory ForensicsVulnerability AnalysisExploitationInformation GatheringWeb SecurityLearning & Education
GitHub0xblackash/cve-2026-8451

CVE-2026-8451

CVE-2026-8451

View Repository
1112 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-8451 - NetScaler SAML IdP Memory Overread Vulnerability

ChatGPT Image Jul 3, 2026, 05_40_38 PM



A pre-authentication memory disclosure vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway configured as a SAML Identity Provider (IdP).


✨ Overview

CVE-2026-8451 is a High-Severity memory disclosure vulnerability caused by an Out-of-Bounds Read (CWE-125) during SAML Identity Provider request processing.

An unauthenticated attacker can send specially crafted SAML requests to trigger a memory overread, potentially exposing sensitive process memory.


📊 Vulnerability Snapshot

PropertyValue
CVECVE-2026-8451
Severity🔴 High
CVSS8.8
CWECWE-125
Attack VectorNetwork
Authentication❌ None
User Interaction❌ None
Affected Service/saml/login
ImpactMemory Disclosure
Patch Available✅ Yes

🎯 Potential Impact

🔐🍪🧠📍⚠️
Session DataAuth TokensProcess MemoryMemory AddressesDoS

Successful exploitation may expose:

  • Authentication artifacts
  • Runtime secrets
  • Sensitive process memory
  • Session-related information
  • Internal memory structures

🧩 Root Cause

Incoming SAML Request
          │
          ▼
 Improper XML Validation
          │
          ▼
 Out-of-Bounds Read
          │
          ▼
 Memory Disclosure

📦 Affected Products

ProductStatus
NetScaler ADC✅ Affected
NetScaler Gateway✅ Affected

Only systems configured as a SAML Identity Provider (IdP) are vulnerable.


✅ Fixed Versions

Release BranchFixed Version
14.114.1-72.61
13.113.1-63.18
FIPSLatest
NDcPPLatest

🛡️ Mitigation

✔ Upgrade Immediately
✔ Disable SAML IdP if Unused
✔ Restrict Internet Exposure
✔ Monitor /saml/login
✔ Review Authentication Logs
✔ Deploy IDS/IPS Signatures
✔ Detect Memory Disclosure Attempts

🔍 Detection

Monitor for:

  • Excessive requests to /saml/login
  • Malformed XML payloads
  • Unexpected NetScaler crashes
  • Authentication anomalies
  • Suspicious SAML assertions

📈 Exploitation Status

Public ResearchProof of ConceptIn-the-Wild
✅ Available🟡 Partial❌ No Confirmed Reports
[+] CVE-2026-8451 PoC - Ashraf Zaryouh (0xBlackash)
[+] Target: https://target.example.com
[+] Starting memory overread attempts...

[-] Attempt 1/12 (padding 476) - No leak
[-] Attempt 2/12 (padding 508) - No leak
[+] SUCCESS! Memory leak detected (padding: 540)

    Leaked bytes: 312

Hexdump:
  66 6f 6f 62 61 72 00 00  de de de de de de de de   |foobar..........|
  0d 0a 41 75 74 68 65 6e  74 69 63 61 74 69 6f 6e   |..Authentication|
  3a 20 53 65 73 73 69 6f  6e 49 44 3d 78 78 78 78   |: SessionID=xxxx|
  de de de de de de de de  0a 0d 55 73 65 72 2d 41   |..........User-A|
  67 65 6e 74 3a 20 4d 6f  7a 69 6c 6c 61 2f 35 2e   |gent: Mozilla/5.|
  ... (more binary data)

ASCII preview:
foobar......Authentication: SessionID=xxxx......User-Agent: Mozilla/5.

📚 References

  • NIST National Vulnerability Database
  • Citrix Security Advisory
  • watchTowr Labs Research
  • CISA (if added)

⚖️ Disclaimer

This repository is provided for educational, defensive, and cybersecurity research purposes only. It does not include exploit code or instructions for unauthorized access. Always conduct security testing with proper authorization.


⭐ Support

If you found this repository useful, consider giving it a ⭐.

Stay Secure • Patch Early • Defend Continuously

Download Tool