{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/freerdp--3.28.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-67289"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeRDP (\u003c= 3.28.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["FreeRDP"],"content_html":"\u003cp\u003eFreeRDP versions 3.28.0 and earlier contain a critical vulnerability (CVE-2026-67289) stemming from improper validation of CRLF and control characters within the TargetNetAddress field during RDP redirection. When a client is configured to connect via an HTTP proxy, FreeRDP propagates the attacker-controlled input directly into the proxy CONNECT request line and Host header. This flaw enables an attacker operating a malicious RDP server to execute HTTP request smuggling, inject arbitrary HTTP headers, or potentially facilitate further attacks against the proxy infrastructure or the client's internal network traversal. Because the proxy processes these smuggled requests as authenticated or authorized traffic, the impact can include unauthorized resource access or secondary exploitation. Defenders should prioritize updating to FreeRDP 3.29.0 or later to ensure proper sanitization of redirection payloads.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for HTTP request smuggling and header injection through the proxy, which could lead to unauthorized access to internal resources, credential theft, or bypass of proxy-based security controls. This vulnerability affects all environments using FreeRDP as a client when egressing through an HTTP proxy, regardless of the underlying operating system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all FreeRDP client installations to version 3.29.0 or later immediately to apply the required input sanitization for the TargetNetAddress field.\u003c/li\u003e\n\u003cli\u003eReview HTTP proxy logs for anomalous CONNECT requests that contain unexpected control characters or header structure deviations.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of allowing HTTP proxy connections for RDP traffic, and consider transitioning to direct connections or hardened VPN-based access where possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T13:52:15Z","date_published":"2026-08-01T13:50:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-crlf-injection/","summary":"FreeRDP versions through 3.28.0 fail to sanitize control characters in RDP redirection fields, allowing malicious servers to perform HTTP request smuggling or header injection against proxy servers.","title":"CVE-2026-67289: CRLF Injection Vulnerability in FreeRDP","url":"https://feed.craftedsignal.io/briefs/2026-08-freerdp-crlf-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - FreeRDP (\u003c= 3.28.0)","version":"https://jsonfeed.org/version/1.1"}