CVE-2026-67293: FreeRDP before 3.29.0 Improper Certificate Hostname Validation
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tlsmatchhostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as .example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509checkhost() rejects). This weakens TLS server authentication under wildcard-certificate conditions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.29.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67293?
The severity of CVE-2026-67293 is critical with a rating of 9.3.
How do I fix CVE-2026-67293?
To fix CVE-2026-67293, upgrade FreeRDP to version 3.29.0 or later.
What is the risk of CVE-2026-67293?
The risk associated with CVE-2026-67293 is rated at 84, indicating a significant security concern.
What type of vulnerability is CVE-2026-67293?
CVE-2026-67293 is an improper certificate hostname validation vulnerability.
Which versions of FreeRDP are affected by CVE-2026-67293?
FreeRDP versions 3.28.0 and earlier are affected by CVE-2026-67293.