


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers…
Published:
31 July 2026 at 22:00:00
Alert date:
1 August 2026 at 14:10:40
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
FreeRDP versions before 3.29.0 contain a vulnerability in the http_response_recv_body() function that fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses. This flaw allows attackers who control a malicious RD Gateway endpoint to send oversized chunked response bodies to clients. The client-side size limit is bypassed entirely when chunked transfer encoding is used, leading to uncontrolled memory consumption. The impact is a denial-of-service condition through client memory resource exhaustion. Users and organizations relying on FreeRDP for Remote Desktop Gateway connectivity are at risk if they connect to untrusted or compromised RD Gateway servers. The fix is available in FreeRDP 3.29.0 and users are advised to upgrade immediately.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67297
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m
https://www.vulncheck.com/advisories/freerdp-before-resource-exhaustion-via-chunked-http-response
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
