CVE-2026-67289
CRITICALFreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
Title source: cnaDescription
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-mwwh-mhp9-q7vm)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
Patch patch
Patch Commit
https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f
Third Party Advisory third-party-advisory
VulnCheck Advisory: FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection
Scores
CVSS v3
9.8
EPSS
0.0038
EPSS Percentile
30.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-113
Status
published
Products (2)
FreeRDP/FreeRDP
< 3.29.0
FreeRDP/FreeRDP
3.29.0
Published
Aug 01, 2026
Tracked Since
Aug 01, 2026