PT-2026-67277 · Freerdp · Freerdp

CVE-2026-67297

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description The software fails to enforce the RESPONSE SIZE LIMIT when processing HTTP responses using Transfer-Encoding: chunked within the http response recv body() function. An attacker controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources, bypassing the configured size limit.
Recommendations Update to version 3.29.0 or later. As a temporary mitigation, restrict connections to trusted RD Gateway endpoints to prevent interaction with malicious servers.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67297
GHSA-2C6R-4PR4-9X8M

Affected Products

Freerdp