Remote Desktop Protocol Vulnerability in FreeRDP by FreeRDP
CVE-2026-55191

8.7HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55191?

FreeRDP clients prior to version 3.27.0 are affected by a vulnerability that occurs when negotiating RDPGFX AVC444 with an H.264 decoder backend. The flaw arises from the calculation of intermediate YUV444 allocation sizes, where faulty multiplication leads to an undersized buffer allocation. An attacker controlling an RDP server can exploit this vulnerability by supplying specific surface dimensions, potentially resulting in crashes of the client application or enabling remote code execution via heap corruption. This issue has been resolved in version 3.27.0.

Affected Version(s)

FreeRDP < 3.27.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.