Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 03 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. | |
| Title | FreeRDP before 3.29.0 Resource Exhaustion via chunked HTTP response | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T18:26:50.551Z
Reserved: 2026-07-29T13:01:57.548Z
Link: CVE-2026-67297
Updated: 2026-08-03T18:26:46.303Z
Status : Received
Published: 2026-08-01T13:16:58.967
Modified: 2026-08-03T19:16:50.280
Link: CVE-2026-67297
OpenCVE Enrichment
Updated: 2026-08-02T03:30:14Z
-
CWE-770
Allocation of Resources Without Limits or Throttling