FreeRDP before 3.29.0 contains a denial of service...
High severity
Unreviewed
Published
Aug 1, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 1, 2026
Published to the GitHub Advisory Database
Aug 1, 2026
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
References