CVE-2026-67297Disclosure(freerdp / freerdp)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch freerdp freerdp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freerdp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
freerdp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-02: 2Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-02: 208-02
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-67297 - DoS in FreeRDP before 3.29.0. Malicious RD Gateway can send oversized chunked HTTP responses, exhausting client memory. CVSS 7.5. Unpatched - monitor for updates. #CVE #FreeRDP #infosec #devsecops #devops #developer #sysadmin #cybersecurityawareness #cybersecuritynews #cyebrsecuritytips #redteam #blueteam https://www.valtersit.com/cve/CVE-2026-67297

    Post summary

    The text reports a new DoS vulnerability (CVE‑2026‑67297) in FreeRDP before version 3.29.0, caused by oversized chunked HTTP responses from a malicious RD Gateway, with a CVSS score of 7.5, and urges users to monitor for updates as no patch has been released yet.

    0000069
    979 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    FreeRDP versions before 3.29.0 contain a CVSS 8.7 flaw in chunked HTTP response handling for RD Gateway. Update promptly if deployed. https://nvd.nist.gov/vuln/detail/CVE-2026-67297 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/yPOABQHuLn

    Post summary

    A high‑severity vulnerability (CVSS 8.7) affecting FreeRDP versions before 3.29.0 is identified; the post urges users to apply the available patch promptly.

    0000048
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreerdpfreerdp---

Explore more