HTTP Proxy Request Injection Vulnerability in FreeRDP by FreeRDP
CVE-2026-67289

9.3CRITICAL

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67289?

In FreeRDP versions prior to 3.29.0, a vulnerability allows a malicious or compromised RDP server to manipulate the TargetNetAddress field in redirection PDUs. Due to inadequate validation of CRLF and control characters, an attacker can inject arbitrary headers or requests into the HTTP proxy CONNECT request generated by the client. This occurs when the compromised value is copied directly into the client's ServerHostname and sent through an HTTP proxy, leading to potential exposure of sensitive information or manipulation of proxy behavior.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

1121984919
.