PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67297 FreeRDP CVE debrief

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. This vulnerability affects FreeRDP, a remote desktop protocol implementation, and the vulnerability class involves a failure to properly handle HTTP responses. The likely operational impact is memory exhaustion. Defenders should verify the affected scope, review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Further investigation is needed to determine the affected scope and potential impact, given the limited information available in the CVE record and NVD entry.

Vendor
FreeRDP
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

Users of FreeRDP versions before 3.29.0 should update to the latest version to prevent potential memory exhaustion attacks. Affected operators include those managing RD Gateway endpoints, and affected platforms include systems using FreeRDP for remote desktop connections. Vulnerability management teams should prioritize updating FreeRDP, and security teams should monitor for suspicious activity and exception tracking.

Technical summary

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). This vulnerability allows attackers controlling a malicious RD Gateway endpoint to send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. The affected product is FreeRDP, and the vulnerability class involves a failure to properly handle HTTP responses. The likely operational impact is memory exhaustion, and defenders should focus on updating FreeRDP to version 3.29.0 or later and implementing compensating controls.

Defensive priority

High-priority defensive actions are required to address this vulnerability, as it can lead to memory exhaustion.

Recommended defensive actions

  • Update FreeRDP to version 3.29.0 or later
  • Implement compensating controls to detect and prevent oversized chunked response bodies
  • Monitor for suspicious activity and exception tracking
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the affected scope and potential impact. The vulnerability affects FreeRDP versions before 3.29.0 and involves a failure to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. Defenders should verify the affected scope, review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:58.967Z and has not been modified since then.