CVE-2026-67293: Freerdp

Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions.

Affected products

  • Freerdp Freerdp: before 3.29.0 (fixed in 3.29.0)

Published 2026-08-01. Last modified 2026-09-29.