What is CVE-2026-67297?
FreeRDP versions before 3.29.0 fail to enforce the RESPONSE_SIZE_LIMIT when processing 'Transfer-Encoding: chunked' HTTP responses in the `http_response_recv_body()` function. This vulnerability allows attackers controlling a malicious RD Gateway endpoint to send oversized response bodies and exhaust client memory resources. Users must upgrade to FreeRDP version 3.29.0 or later immediately.
Azərbaycanca: FreeRDP-nin 3.29.0 əvvəlki versiyalarında `http_response_recv_body()` funksiyasında `Transfer-Encoding: chunked` HTTP cavabları işlənərkən `RESPONSE_SIZE_LIMIT` düzgün tətbiq edilmir. Bu zəiflik, təcavüzkara nəzarət etdiyi zərərli RD Gateway endpoint vasitəsilə həddindən artıq böyük cavab gövdələri göndərərək istifadəçi resurslarını tükətməyə imkan yaradır. FreeRDP istifadəçiləri dərhal 3.29.0 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: FreeRDP
FAQ2
In which FreeRDP function was the CVE-2026-67297 vulnerability discovered?
The CVE-2026-67297 vulnerability was discovered in the `http_response_recv_body()` function of FreeRDP.
To which version must FreeRDP be updated to protect against CVE-2026-67297?
To protect against CVE-2026-67297, FreeRDP must be updated immediately to version 3.29.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.