FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
Published Aug 1, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.43%
Description
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
Affected products
-
- Version 0StatusaffectedConstraints<3.29.0
- Version 3.29.0StatusunaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
freerdp-2:3.10.3-12.el10_2.8
Fixed · RHSA-2026:54486
Red Hat Enterprise Linux 10.0 Extended Update Support
freerdp-2:3.10.3-3.el10_0.11
Fixed · RHSA-2026:58711
Red Hat Enterprise Linux 7 Extended Lifecycle Support
freerdp-0:2.1.1-5.el7_9.11
Fixed · RHSA-2026:62401
Red Hat Enterprise Linux 8
freerdp-2:2.11.7-11.el8_10
Fixed · RHSA-2026:54485
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
freerdp-2:2.2.0-14.el8_4.2
Fixed · RHSA-2026:60173
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
freerdp-2:2.2.0-14.el8_4.2
Fixed · RHSA-2026:60173
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
freerdp-2:2.2.0-7.el8_6.11
Fixed · RHSA-2026:61250
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
freerdp-2:2.2.0-7.el8_6.11
Fixed · RHSA-2026:61250
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
freerdp-2:2.2.0-12.el8_8.10
Fixed · RHSA-2026:61251
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
freerdp-2:2.2.0-12.el8_8.10
Fixed · RHSA-2026:61251
Red Hat Enterprise Linux 9
freerdp-2:2.11.7-7.el9_8.5
Fixed · RHSA-2026:54487
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
freerdp-2:2.4.1-6.el9_2.11
Fixed · RHSA-2026:58712
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
freerdp-2:2.11.2-1.el9_4.10
Fixed · RHSA-2026:58710
Red Hat Enterprise Linux 9.6 Extended Update Support
freerdp-2:2.11.7-1.el9_6.12
Fixed · RHSA-2026:58713
Red Hat Enterprise Linux 6
freerdp
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp-2:3.10.3-12.el10_2.8 | Fixed | RHSA-2026:54486 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freerdp-2:3.10.3-3.el10_0.11 | Fixed | RHSA-2026:58711 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | freerdp-0:2.1.1-5.el7_9.11 | Fixed | RHSA-2026:62401 |
| Red Hat Enterprise Linux 8 | freerdp-2:2.11.7-11.el8_10 | Fixed | RHSA-2026:54485 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | freerdp-2:2.2.0-14.el8_4.2 | Fixed | RHSA-2026:60173 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | freerdp-2:2.2.0-14.el8_4.2 | Fixed | RHSA-2026:60173 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | freerdp-2:2.2.0-7.el8_6.11 | Fixed | RHSA-2026:61250 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | freerdp-2:2.2.0-7.el8_6.11 | Fixed | RHSA-2026:61250 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | freerdp-2:2.2.0-12.el8_8.10 | Fixed | RHSA-2026:61251 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | freerdp-2:2.2.0-12.el8_8.10 | Fixed | RHSA-2026:61251 |
| Red Hat Enterprise Linux 9 | freerdp-2:2.11.7-7.el9_8.5 | Fixed | RHSA-2026:54487 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | freerdp-2:2.4.1-6.el9_2.11 | Fixed | RHSA-2026:58712 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | freerdp-2:2.11.2-1.el9_4.10 | Fixed | RHSA-2026:58710 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | freerdp-2:2.11.7-1.el9_6.12 | Fixed | RHSA-2026:58713 |
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Moderate: This client-side vulnerability in FreeRDP allows for HTTP proxy request injection. Exploitation requires a FreeRDP client to be configured to use an HTTP proxy and to connect to a malicious or compromised RDP server, which then sends a crafted redirection PDU. This limits the attack surface to specific client configurations and interactions with untrusted RDP endpoints.
Red Hat mitigation
To mitigate this issue, FreeRDP clients should avoid connecting to untrusted RDP servers when configured to use an HTTP proxy. Alternatively, if connecting to potentially untrusted RDP servers, disable the HTTP proxy configuration for FreeRDP.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-67289 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510004 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-51840 Advisory
- https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f patch
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-67289
- https://www.cve.org/CVERecord?id=CVE-2026-67289
- https://www.vulncheck.com/advisories/freerdp-before-http-proxy-request-injection-via-redirection third-party-advisory
Change history (0)
No recorded changes yet.