CVE-2026-67297

FreeRDP · FreeRDP

FreeRDP is vulnerable to resource exhaustion through improper handling of chunked HTTP responses, which can be exploited by an unauthenticated attacker to cause a denial of service.

Executive summary

A critical resource exhaustion vulnerability in FreeRDP prior to 3.29.0 allows unauthenticated remote attackers to cause service instability.

Vulnerability

This issue involves the allocation of resources without limits or throttling (CWE-770) when processing chunked HTTP responses. An unauthenticated attacker can leverage this to exhaust system resources, leading to a denial of service.

Business impact

The potential for resource exhaustion poses a direct threat to the availability of systems relying on FreeRDP. With a CVSS score of 7.5, this vulnerability represents a high risk to operational uptime and should be addressed promptly to prevent exploitation-induced outages.

Remediation

Immediate Action: Upgrade to FreeRDP version 3.29.0 or higher to implement the required resource management patches.

Proactive Monitoring: Monitor memory and CPU usage on servers running FreeRDP to identify potential resource exhaustion spikes indicative of an attack.

Compensating Controls: Utilize a Web Application Firewall or similar traffic filtering solution to inspect and limit malformed or excessive HTTP traffic directed at the service.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Maintaining system availability is paramount, and this vulnerability directly threatens that goal. Organizations must prioritize the deployment of version 3.29.0 to remediate the resource management flaw and protect against potential service degradation.