CVE-2026-67297: Freerdp
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
Affected products
- Freerdp Freerdp: before 3.29.0 (fixed in 3.29.0)
Published 2026-08-01. Last modified 2026-09-11.