Out-of-Bounds Read Vulnerability in xrdp by Neutrinolabs
CVE-2026-33516

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
17 April 2026

What is CVE-2026-33516?

xrdp, an open source Remote Desktop Protocol (RDP) server, exhibits an out-of-bounds read vulnerability during the RDP capability exchange phase. This flaw arises from memory being accessed without proper validation of the remaining buffer length. A remote and unauthenticated attacker could exploit this vulnerability by sending a specially crafted Confirm Active PDU, potentially leading to a denial of service through process crashes or the unauthorized disclosure of sensitive information from process memory. Users are advised to update to version 0.10.6 or later for protection against this vulnerability.

Affected Version(s)

xrdp < 0.10.6

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.