CVE-2026-67289 CRITICAL

CVE-2026-67289: FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

Vendor Freerdp
Product FreeRDP
Weakness CWE-113 · HTTP response splitting
Published August 1, 2026
Last update August 5, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.

Key dates

02Disclosure timeline

August 1, 2026 CVE published
August 5, 2026 Record updated