TLS Certificate Identity Validation Weakness in FreeRDP by FreeRDP
CVE-2026-66402
9.3CRITICAL
What is CVE-2026-66402?
FreeRDP, prior to version 3.29.0, contains multiple vulnerabilities in its TLS certificate identity validation procedures. Specifically, it uses custom methods for matching Common Names and DNS Subject Alternative Names (SANs), which expose several security flaws. These issues include truncating DNS SAN values at embedded NUL bytes, incorrectly accepting a Common Name despite the presence of non-matching DNS SAN entries, and allowing IP-literal targets without proper comparison to iPAddress SANs. Consequently, attackers with an ability to present a trusted or misissued certificate can potentially bypass server identity verification, leading to significant risks in TLS server authentication.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
