Skip to content

fix: add NetScaler security bulletins and stop false positives from CVE-record build bounds - #84

Merged
TITeee merged 2 commits into
mainfrom
fix/netscaler-cna-build-bounds
Oct 9, 2026
Merged

TITeee merged 2 commits into
mainfrom
fix/netscaler-cna-build-bounds

Conversation

@TITeee

@TITeee TITeee commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Problem

NetScaler CVE records give a release branch and a build separately (version: "14.1", lessThan: "56.73", versionType: "patch"). The CNA fetcher read this as 14.1.0 up to 56.73.0, which covers every later build of the branch, so fixed builds (for example 14.1-56.73 and 14.1-60.52 for CVE-2025-12101) were reported as affected.

Changes

  • CNA fetcher: drop NetScaler branch-and-build ranges (netscalerBuildBound). A migration (migrate:remove-netscaler-cna-build-ranges) deletes the 102 rows already stored. Until the advisory source below runs, affected NetScaler builds are not reported from CVE records.
  • NetScaler advisory source (advisory-citrix, daily 16:45 UTC, about 20 pages over plain HTTP, no browser): reads the ADC / Gateway / Console security bulletins of 2022 and later from support.citrix.com and stores one advisory per CVE with the first fixed build of each release branch.
    • A NetScaler version is a branch and a build (14.1-73.32) and gets its own ordering (citrix-version.ts).
    • FIPS / NDcPP builds use their own numbering and are a separate product.
    • A branch the bulletin calls end of life and vulnerable is stored as out_of_support.
    • Lines under a CVE-x: heading or "affected by CVE-x" apply to that CVE only, including a single affected build (CVE-2026-4368).
    • A fixed build written with a dot (12.1.65.21) is read as 12.1-65.21.
  • Product aliases: NetScaler / Citrix names and the NVD CPE tokens map to the stored names. Each list keeps the NVD tokens so NVD results are not lost.
  • Docs: data sources, operations, architecture, known issues, README.

Scope limits

Bulletins before 2022 (for example CVE-2019-19781), other Citrix products (Workspace app, StoreFront, XenServer, SD-WAN) and CVEs whose bulletin is not published yet are not covered. Documented in known issues.

Test plan

  • vitest (702 tests), tsc --noEmit, eslint src
  • Local import: 40 advisories, 0 failed
  • Probe: fixed builds are no longer reported; affected builds are, with the right fixedVersion; the CitrixBleed (CVE-2023-4966) boundary is correct
  • After deploy, run pnpm import:citrix once instead of waiting for the 16:45 job

TITeee added 2 commits October 9, 2026 15:30
… plain versions

NetScaler's CVE record ranges give a release branch and a build separately
(version "14.1", lessThan "56.73", versionType "patch"). They were read as
14.1.0 up to 56.73.0, which covers every later build of the branch, so fixed
builds such as 14.1-56.73 and 14.1-60.52 were reported as affected.

Drop these ranges in the CNA fetcher and add a migration that removes the rows
already stored. Until the dedicated NetScaler advisory source lands, affected
NetScaler builds are not reported from CVE records.
Read the NetScaler ADC / Gateway / Console security bulletins of 2022 and
later from support.citrix.com over plain HTTP (about 20 pages, daily at
16:45 UTC) and store one advisory per CVE with the first fixed build of each
release branch.

- A NetScaler version is a branch and a build ("14.1-73.32"). It gets its own
  ordering (citrix-version.ts), since the generic encoding keeps only the 73
  of 73.32.
- FIPS / NDcPP builds run on their own numbering and are a separate product.
- A branch the bulletin calls end of life and vulnerable is stored as
  out_of_support. Lines under a "CVE-x:" heading or "affected by CVE-x"
  apply to that CVE only, including a single affected build.
- A fixed build written with a dot ("12.1.65.21") is read as 12.1-65.21.
- Product aliases map NetScaler / Citrix names and the NVD CPE tokens to the
  stored names.
@TITeee
TITeee merged commit 551ba05 into main Oct 9, 2026
4 checks passed
@TITeee
TITeee deleted the fix/netscaler-cna-build-bounds branch October 9, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant