


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_host…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:40
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access
FreeRDP versions up to and including 3.28.0 contain multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). The vulnerabilities stem from FreeRDP performing custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs. Three distinct bypass vectors exist: NUL byte truncation in DNS SAN values, accepting a matching CN when non-matching DNS SANs are present, and accepting IP-literal targets via DNS/CN matching without comparing iPAddress SANs. An attacker with a trusted or misissued certificate chain can exploit these weaknesses to bypass server identity verification and weaken TLS server authentication. The issue is fixed in FreeRDP 3.29.0. Users should upgrade immediately to mitigate the risk of man-in-the-middle attacks against RDP sessions.
Technical details
Mitigation steps:
Affected products:
FreeRDP <= 3.28.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-66402
https://github.com/FreeRDP/FreeRDP/commit/b9533f07f98c25ed01c5f543b4d0ce73e120f5fd
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-43hh-p3vw-hfx3
https://www.vulncheck.com/advisories/freerdp-before-tls-certificate-identity-validation-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
