<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:48.892285+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:54485</id>
    <title>ALSA-2026:54485 — Important: freerdp security update</title>
    <updated>2026-10-02T14:54:48.912815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: freerdp, AlmaLinux:8: freerdp-devel, AlmaLinux:8: freerdp-libs, AlmaLinux:8: libwinpr, AlmaLinux:8: libwinpr-devel</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.</p>
<p>Security Fix(es):</p>
<p>* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)
  * FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)
  * FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)
  * FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:54485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10983</id>
    <title>bdu:2026-10983</title>
    <updated>2026-10-02T14:54:48.912883+00:00</updated>
    <content>bdu:2026-10983</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10983"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348491</id>
    <title>EUVD-2026-348491</title>
    <updated>2026-10-02T14:54:48.912900+00:00</updated>
    <content>EUVD-2026-348491</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348491"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67289</id>
    <title>fkie_cve-2026-67289</title>
    <updated>2026-10-02T14:54:48.912912+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3x8f-6ffv-v2wc</id>
    <title>GHSA-3x8f-6ffv-v2wc</title>
    <updated>2026-10-02T14:54:48.912937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3x8f-6ffv-v2wc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3853</id>
    <title>OESA-2026-3853 — freerdp security update</title>
    <updated>2026-10-02T14:54:48.912955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP4: freerdp</p>
<p>FreeRDP is a client implementation of the Remote Desktop Protocol (RDP) that follows Microsoft&amp;amp;apos;s
open specifications. This package provides the client applications xfreerdp.

Security Fix(es):</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.1, a global-buffer-overflow vulnerability was observed in FreeRDP&amp;apos;s Base64 decoding path. The root cause is the implementation-defined signedness of the `char` type: on Arm/AArch64 builds, plain `char` is treated as unsigned, causing the guard condition `c &amp;lt;= 0` to potentially be optimized by the compiler into a simple `c != 0` check. Consequently, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, resulting in out-of-bounds access. A malicious server can exploit this to trigger a client-side crash, leading to a denial of service.(CVE-2026-22858)</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP&amp;apos;s planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54485</id>
    <title>RHSA-2026:54485 — Red Hat Security Advisory: freerdp security update</title>
    <updated>2026-10-02T14:54:48.913008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:58710</id>
    <title>RHSA-2026:58710 — Red Hat Security Advisory: freerdp security update</title>
    <updated>2026-10-02T14:54:48.913030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:58710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:54485</id>
    <title>RLSA-2026:54485 — Important: freerdp security update</title>
    <updated>2026-10-02T14:54:48.913048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: freerdp</p>
<p>FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.</p>
<p>Security Fix(es):</p>
<p>* FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624)</p>
<p>* FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299)</p>
<p>* FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289)</p>
<p>* FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:54485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67289</id>
    <title>UBUNTU-CVE-2026-67289</title>
    <updated>2026-10-02T14:54:48.913072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: freerdp, Ubuntu:Pro:18.04:LTS: freerdp2, Ubuntu:18.04:LTS: freerdp, Ubuntu:Pro:20.04:LTS: freerdp2, Ubuntu:22.04:LTS: freerdp2, Ubuntu:24.04:LTS: freerdp3, Ubuntu:Pro:24.04:LTS: freerdp2, Ubuntu:26.04:LTS: freerdp3</p>
<p>FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2384</id>
    <title>WID-SEC-W-2026-2384 — FreeRDP: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:54:48.913103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2384"/>
  </entry>
</feed>
