CVE-2026-67296: FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
Published Aug 1, 2026
·Updated
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Affected Software
1 affected component
FreeRDP freerdp<3.29.0
Event History
Aug 1, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness