FreeRDP

22 known vulnerabilities in FreeRDP, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-91964 CVSS 8.7 high FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection…
  • CVE-2026-91963 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A…
  • CVE-2026-91962 CVSS 5.3 medium FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN…
  • CVE-2026-91961 CVSS 7.1 high FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate…
  • CVE-2026-91960 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers…
  • CVE-2026-91959 CVSS 7.1 high FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser…
  • CVE-2026-91958 CVSS 6.9 medium FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array…
  • CVE-2026-91957 CVSS 2.3 low FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails…
  • CVE-2026-91956 CVSS 7.1 high FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes…
  • CVE-2026-91955 CVSS 8.2 high FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote…
  • CVE-2026-91954 CVSS 7.1 high FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with…
  • CVE-2026-91953 CVSS 7.1 high FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the…
  • CVE-2026-91952 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks…
  • CVE-2026-91951 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's…
  • CVE-2026-91950 CVSS 7.1 high FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer…
  • CVE-2026-91949 CVSS 9.2 critical FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to…
  • CVE-2026-91948 CVSS 7.7 high FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when…
  • CVE-2026-91947 CVSS 7.7 high FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer…
  • CVE-2026-91946 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that…
  • CVE-2026-91945 CVSS 7.1 high FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length…
  • CVE-2026-85090 CVSS 5.3 medium FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane…
  • CVE-2026-85089 CVSS 7.1 high FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields…