CVE-2026-67289

CRITICAL

FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

Title source: cna
STIX 2.1

Description

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-mwwh-mhp9-q7vm)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
Third Party Advisory third-party-advisory
VulnCheck Advisory: FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection

Scores

CVSS v3 9.8
EPSS 0.0038
EPSS Percentile 30.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-113
Status published
Products (2)
FreeRDP/FreeRDP < 3.29.0
FreeRDP/FreeRDP 3.29.0
Published Aug 01, 2026
Tracked Since Aug 01, 2026