VYPR
High severity7.5NVD Advisory· Published Aug 1, 2026· Updated Sep 11, 2026

CVE-2026-67296

CVE-2026-67296

Description

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7

Patches

Vulnerability mechanics

References

2

News mentions

1