Buffer Over-Disclosure in FreeRDP Products by FreeRDP
CVE-2026-67292
9.3CRITICAL
What is CVE-2026-67292?
A buffer over-disclosure vulnerability in FreeRDP's gateway WebSocket transport could allow attackers to exploit the response stream generated by the client. When a malicious WebSocket peer sends a non-empty Ping control frame, the client generates an oversized Pong response. This response leaks data beyond the intended payload, disclosing sensitive information such as the masking key. Furthermore, if a zero-length Ping is sent, it triggers an assertion that causes the client to terminate unexpectedly, potentially leading to a denial of service.
Affected Version(s)
FreeRDP 0 < 3.29.0
FreeRDP 3.29.0
