FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planardecompressplanerleonly in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFXCMDIDWIRETOSURFACE1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.