GHSA-xq3v-xj62-r99vHighCVSS 7.5

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel...

Published
August 1, 2026
Last Modified
August 1, 2026

🔗 CVE IDs covered (1)

📋 Description

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

🔗 References (4)