<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>FreeRDP (&lt;= 3.28.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/freerdp--3.28.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 01 Aug 2026 13:50:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/freerdp--3.28.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-67289: CRLF Injection Vulnerability in FreeRDP</title><link>https://feed.craftedsignal.io/briefs/2026-08-freerdp-crlf-injection/</link><pubDate>Sat, 01 Aug 2026 13:50:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-freerdp-crlf-injection/</guid><description>FreeRDP versions through 3.28.0 fail to sanitize control characters in RDP redirection fields, allowing malicious servers to perform HTTP request smuggling or header injection against proxy servers.</description><content:encoded><![CDATA[<p>FreeRDP versions 3.28.0 and earlier contain a critical vulnerability (CVE-2026-67289) stemming from improper validation of CRLF and control characters within the TargetNetAddress field during RDP redirection. When a client is configured to connect via an HTTP proxy, FreeRDP propagates the attacker-controlled input directly into the proxy CONNECT request line and Host header. This flaw enables an attacker operating a malicious RDP server to execute HTTP request smuggling, inject arbitrary HTTP headers, or potentially facilitate further attacks against the proxy infrastructure or the client's internal network traversal. Because the proxy processes these smuggled requests as authenticated or authorized traffic, the impact can include unauthorized resource access or secondary exploitation. Defenders should prioritize updating to FreeRDP 3.29.0 or later to ensure proper sanitization of redirection payloads.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for HTTP request smuggling and header injection through the proxy, which could lead to unauthorized access to internal resources, credential theft, or bypass of proxy-based security controls. This vulnerability affects all environments using FreeRDP as a client when egressing through an HTTP proxy, regardless of the underlying operating system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all FreeRDP client installations to version 3.29.0 or later immediately to apply the required input sanitization for the TargetNetAddress field.</li>
<li>Review HTTP proxy logs for anomalous CONNECT requests that contain unexpected control characters or header structure deviations.</li>
<li>Evaluate the necessity of allowing HTTP proxy connections for RDP traffic, and consider transitioning to direct connections or hardened VPN-based access where possible.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>