Description
FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Double Free
Action: Patch
AI Analysis

Impact

FreeRDP client versions prior to 3.31.0 are vulnerable to an integer overflow in WinPR's Stream_EnsureRemainingCapacity routine. When a remote RD Gateway peer sends a WebSocket Ping frame with a 64-bit extended payload length crafted to wrap the internal counter, the overflow leads to a double free that crashes the client. The crash results in a denial-of-service condition for the user, without compromising data confidentiality or integrity.

Affected Systems

Any installation of the FreeRDP client running a version earlier than 3.31.0. The vulnerability is tied to the client’s WebSocket handling path and affects all platforms supported by the project.

Risk and Exploitability

The flaw carries a CVSS score of 7.1, reflecting moderate‑to‑high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation attempts are currently rare and not widely observed. However, an attacker who can inject traffic into the client via a malicious RD Gateway or otherwise force the client to process a crafted WebSocket Ping frame can trigger the double free, causing a crash and terminating the user session. The risk is therefore primarily denial of service to clients that accept connections from untrusted gateways.

Generated by OpenCVE AI on September 20, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FreeRDP to version 3.31.0 or newer, which eliminates the integer overflow and double free.
  • Limit incoming RD Gateway connections to trusted hosts or networks to prevent malicious WebSocket Ping frames from reaching the client.
  • Enable monitoring of client crash reports and network traffic for anomalous WebSocket activity to detect attempts to exploit the vulnerability.

Generated by OpenCVE AI on September 20, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.
Title FreeRDP before 3.31.0 Integer Overflow Double Free
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-190
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:56:30.601Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91960

cve-icon Vulnrichment

Updated: 2026-09-15T15:55:29.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:51.070

Modified: 2026-09-24T12:17:24.547

Link: CVE-2026-91960

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:14Z

Links: CVE-2026-91960 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound