PT-2026-67277 · Freerdp · Freerdp
CVE-2026-67297
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.29.0
Description
The software fails to enforce the
RESPONSE SIZE LIMIT when processing HTTP responses using Transfer-Encoding: chunked within the http response recv body() function. An attacker controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources, bypassing the configured size limit.Recommendations
Update to version 3.29.0 or later.
As a temporary mitigation, restrict connections to trusted RD Gateway endpoints to prevent interaction with malicious servers.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp