CVE-2026-67292Freerdp · Freerdp
Vulnerability data via NVD (ingested)
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-67292product:"Freerdp Freerdp"http.html:"Freerdp"More intel sources (5)
vuln:CVE-2026-67292vulnerabilities.cve_id: CVE-2026-67292CVE-2026-67292CVE-2026-67292"CVE-2026-67292" exploit -site:nvd.nist.gov