


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress fiel…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:47
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
FreeRDP versions 3.28.0 and earlier are vulnerable to HTTP proxy request injection due to insufficient validation of the server-controlled RDP redirection TargetNetAddress field. The field is not sanitized for CRLF or control characters before being written into HTTP proxy CONNECT requests and Host headers. A malicious or compromised RDP server can exploit this by sending a crafted redirection PDU with embedded control characters, allowing arbitrary header and request injection into the HTTP proxy CONNECT stream. This could enable traffic hijacking, cache poisoning, or other proxy-level attacks. The vulnerability is fixed in FreeRDP 3.29.0. A GitHub commit and security advisory are available detailing the patch. Users connecting through HTTP proxies are most at risk. The issue is tracked under GHSA-mwwh-mhp9-q7vm and documented by VulnCheck.
Technical details
Mitigation steps:
Affected products:
FreeRDP <= 3.28.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67289
https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
