Back

CRITICAL

FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

Published Aug 1, 2026

Description

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

Affected products

Remediation

Red Hat statement

Moderate: This client-side vulnerability in FreeRDP allows for HTTP proxy request injection. Exploitation requires a FreeRDP client to be configured to use an HTTP proxy and to connect to a malicious or compromised RDP server, which then sends a crafted redirection PDU. This limits the attack surface to specific client configurations and interactions with untrusted RDP endpoints.

Red Hat mitigation

To mitigate this issue, FreeRDP clients should avoid connecting to untrusted RDP servers when configured to use an HTTP proxy. Alternatively, if connecting to potentially untrusted RDP servers, disable the HTTP proxy configuration for FreeRDP.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 1, 2026
Updated Aug 5, 2026
Reserved Jul 29, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Aug 1, 2026
ENISA EUVD
Assigner VulnCheck
Published Aug 1, 2026
Updated Aug 5, 2026
Exploited since n/a
EUVD-2026-51840