CVE-2026-67297
PoC massUnbounded memory exhaustion in FreeRDP via malicious RD Gateway chunked responses
FreeRDP before 3.29.0 fails to enforce the configured RESPONSE_SIZE_LIMIT when reading HTTP responses that use Transfer-Encoding: chunked in http_response_recv_body(), so an oversized chunked body is accepted without any effective cap. An attacker controlling a malicious or compromised Remote Desktop Gateway endpoint can feed a connecting FreeRDP client an effectively unlimited response body, exhausting client memory and causing a crash or hang; the CVSS 4.0 score of 8.7 reflects high availability impact only, with no confidentiality or integrity impact. Any user or application that uses FreeRDP (the xfreerdp client and embedders such as Remmina, Apache Guacamole, and thin-client vendors) to connect through an RD Gateway is affected. No in-the-wild exploitation is known: the flaw is absent from CISA KEV, EPSS is a low 0.3% (27th percentile), and the only public reference is the vendor's GitHub security advisory. The flaw is fixed in FreeRDP 3.29.0.
What to do: Upgrade to FreeRDP 3.29.0 or later and rebuild or repackage dependent applications (e.g., Remmina, Apache Guacamole) against the patched library. Until patched, restrict RDP-over-Gateway connections to trusted, known RD Gateways, keep gateway TLS certificate validation enabled, and monitor FreeRDP-based client processes for abnormal memory growth.
| FreeRDP | all versions before 3.29.0 (fixed in 3.29.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
- Vendors
- freerdp
- Products
- freerdp
- Weakness
- CWE-770
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.