CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-01 13:16

Updated : 2026-09-11 21:04


NVD link : CVE-2026-67297

Mitre link : CVE-2026-67297

CVE.ORG link : CVE-2026-67297


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-770

Allocation of Resources Without Limits or Throttling