


Perceptive Security
SOC/SIEM Consultancy

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before strea…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:40
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
FreeRDP versions before 3.29.0 contain a denial of service vulnerability in the RDPEI server channel handler. The handler fails to validate the maximum PDU body length prior to stream allocation. A malicious RDP client can exploit this by sending a header-only RDPEI message with an inflated declared body length. This causes the server to allocate excessive memory, potentially leading to resource exhaustion and denial of service. The vulnerability resides in the server-side component, meaning it can be triggered remotely by any connecting RDP client. A fix is available in FreeRDP 3.29.0. Users and system administrators running FreeRDP as an RDP server should upgrade immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
FreeRDP
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67296
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v
https://www.vulncheck.com/advisories/freerdp-before-denial-of-service-via-rdpei-pdu
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
