Description
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Published: 2026-08-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreeRDP before version 3.29.0 contains a flaw in the RDPEI server channel handler that does not validate the maximum PDU body length before allocating memory. A malicious RDP client can send a header-only RDPEI message with a very large declared body length, which forces the server to allocate excessive memory and can cause the process to crash or become unresponsive. The resulting denial of service disables legitimate Remote Desktop connections to the affected server.

Affected Systems

The vulnerability affects the FreeRDP project, specifically all releases of the FreeRDP client that run a server component before update version 3.29.0. Users deploying older FreeRDP binaries for Windows Remote Desktop or virtual desktop delivery should verify their install falls into this range.

Risk and Exploitability

With a CVSS score of 8.7, the weakness is considered high severity. The EPSS score is not provided, so the exploitation likelihood is uncertain from that metric, but the vulnerability is remotely exploitable by any RDP client capable of crafting malformed RDPEI PDUs. The CISA KEV catalog does not list this CVE, indicating no known active exploits at the time of assessment. Nonetheless, the potential for serious service disruption warrants immediate attention and remediation.

Generated by OpenCVE AI on August 2, 2026 at 03:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.29.0 or later.
  • Configure firewall or network controls to restrict RDPEI channel traffic from untrusted sources.
  • Monitor the FreeRDP service for abnormal memory consumption or crashes and administer alerts accordingly.

Generated by OpenCVE AI on August 2, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 01 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
Title FreeRDP before 3.29.0 Denial of Service via RDPEI PDU
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-20
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-03T17:45:21.975Z

Reserved: 2026-07-29T13:01:57.548Z

Link: CVE-2026-67296

cve-icon Vulnrichment

Updated: 2026-08-03T17:44:58.411Z

cve-icon NVD

Status : Received

Published: 2026-08-01T13:16:58.830

Modified: 2026-08-03T18:16:40.860

Link: CVE-2026-67296

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-01T12:22:17Z

Links: CVE-2026-67296 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T03:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation