What is CVE-2026-67289?
CVE-2026-67289 is a vulnerability in FreeRDP client (versions <= 3.28.0) where CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field are not validated. This can lead to HTTP request smuggling or header injection when the client connects through an HTTP proxy. Upgrading to FreeRDP 3.29.0 is recommended.
Azərbaycanca: CVE-2026-67289 FreeRDP müştərisində (3.28.0 və əvvəlki versiyalar) server tərəfindən idarə olunan RDP yönləndirmə 'TargetNetAddress' sahəsində CRLF və nəzarət simvollarının yoxlanılmaması zəifliyidir. Bu, müştəri HTTP proxy ilə qoşulduqda proxy sorğusuna header injection və ya cavab bölmə hücumlarına səbəb ola bilər. FreeRDP-i 3.29.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of FreeRDP are affected by CVE-2026-67289?
FreeRDP client versions 3.28.0 and earlier are affected by this vulnerability.
What type of attacks can CVE-2026-67289 lead to?
This vulnerability can lead to header injection or response splitting attacks when the client connects through an HTTP proxy.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.