CVE-2026-67296 UNKNOWN

CVE-2026-67296

Published: 2026-08-01

Description

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…