Buffer Over-Disclosure in FreeRDP Products by FreeRDP
CVE-2026-67292

9.3CRITICAL

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
1 August 2026

What is CVE-2026-67292?

A buffer over-disclosure vulnerability in FreeRDP's gateway WebSocket transport could allow attackers to exploit the response stream generated by the client. When a malicious WebSocket peer sends a non-empty Ping control frame, the client generates an oversized Pong response. This response leaks data beyond the intended payload, disclosing sensitive information such as the masking key. Furthermore, if a zero-length Ping is sent, it triggers an assertion that causes the client to terminate unexpectedly, potentially leading to a denial of service.

Affected Version(s)

FreeRDP 0 < 3.29.0

FreeRDP 3.29.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.