HTTP Proxy Request Injection Vulnerability in FreeRDP by FreeRDP
CVE-2026-67289
9.3CRITICAL
What is CVE-2026-67289?
In FreeRDP versions prior to 3.29.0, a vulnerability allows a malicious or compromised RDP server to manipulate the TargetNetAddress field in redirection PDUs. Due to inadequate validation of CRLF and control characters, an attacker can inject arbitrary headers or requests into the HTTP proxy CONNECT request generated by the client. This occurs when the compromised value is copied directly into the client's ServerHostname and sent through an HTTP proxy, leading to potential exposure of sensitive information or manipulation of proxy behavior.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
