๐จ CVE-2026-91949
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
๐@cveNotify
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
๐@cveNotify
GitHub
FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS
# FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS
Discovery credit: Bynario Atlas
CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N` (9.3, Cr...
Discovery credit: Bynario Atlas
CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N` (9.3, Cr...
๐จ CVE-2026-91950
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
๐@cveNotify
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass bounds checks and trigger memory reads past the packet buffer, causing client crashes or heap disclosure in logs.
๐@cveNotify
GitHub
RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard
### Summary
FreeRDP's RDPDR channel packet dump routine (`rdpdr_dump_packet` in `libfreerdp/utils/rdpdr_utils.c`) performs an out-of-bounds read (CWE-125) in the `PAKID_CORE_CLIENT_NAME` cas...
FreeRDP's RDPDR channel packet dump routine (`rdpdr_dump_packet` in `libfreerdp/utils/rdpdr_utils.c`) performs an out-of-bounds read (CWE-125) in the `PAKID_CORE_CLIENT_NAME` cas...
๐จ CVE-2026-91951
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.
๐@cveNotify
GitHub
Out-of-bounds write in urb_send_current_frame_number_result (urbdrc client channel)
## Summary
A malicious or compromised RDP server can make a FreeRDP client write 4 bytes past the end of a
16 byte heap allocation by sending a single 28 byte USB redirection message.
`urb_s...
A malicious or compromised RDP server can make a FreeRDP client write 4 bytes past the end of a
16 byte heap allocation by sending a single 28 byte USB redirection message.
`urb_s...
๐จ CVE-2026-91952
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
๐@cveNotify
GitHub
Infinite loop / CPU DoS in pool_decode_rect
The report was generated by AI and has been reviewed manually.
### Summary
Infinite loop / CPU DoS in pool_decode_rect when numRegionRects
exceeds work_object_count: a malicious RDP server...
### Summary
Infinite loop / CPU DoS in pool_decode_rect when numRegionRects
exceeds work_object_count: a malicious RDP server...
๐จ CVE-2026-91953
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
๐@cveNotify
FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server Redirection PDU with an oversized LB_LOAD_BALANCE_INFO value to overflow the buffer with attacker-controlled content, causing denial of service or heap corruption before authentication completes.
๐@cveNotify
GitHub
Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token
# Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token
**Reported by:** Feng Xue and XGPT of ThreatBook
## Affected versions
- master @ 20...
**Reported by:** Feng Xue and XGPT of ThreatBook
## Affected versions
- master @ 20...
๐จ CVE-2026-91954
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
๐@cveNotify
FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when the codec is disabled.
๐@cveNotify
GitHub
NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec
## Summary
A malicious RDP server can crash a FreeRDP client by sending one Surface Bits command
that claims to use NSCodec.
The client only allocates the NSCodec decoder when the user asks ...
A malicious RDP server can crash a FreeRDP client by sending one Surface Bits command
that claims to use NSCodec.
The client only allocates the NSCodec decoder when the user asks ...
๐จ CVE-2026-91955
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
๐@cveNotify
FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.
๐@cveNotify
GitHub
FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation โ SIGFPE/assert-abort kills any defaultโฆ
A pre-authentication remote crash of any server built on FreeRDP's server API (`libfreerdp`), caused by trusting client-supplied desktop dimensions during capability negotiation. **Attack direc...
๐จ CVE-2026-91956
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
๐@cveNotify
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
๐@cveNotify
GitHub
URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch
### Summary
FreeRDP's URBDRC (USB device redirection) channel performs a heap out-of-bounds read (CWE-125) in `func_get_ep_desc()` because it indexes `LibusbConfig->interface[]` by the ar...
FreeRDP's URBDRC (USB device redirection) channel performs a heap out-of-bounds read (CWE-125) in `func_get_ep_desc()` because it indexes `LibusbConfig->interface[]` by the ar...
๐จ CVE-2026-91957
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
๐@cveNotify
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
๐@cveNotify
GitHub
[channels,smartcard] worker creation failure frees a devman-owned device
## Summary
The smartcard RDPDR device is registered with devman before its worker thread is created. If `CreateThread(..., CREATE_SUSPENDED, ...)` fails, `DeviceServiceEntry()` frees the already...
The smartcard RDPDR device is registered with devman before its worker thread is created. If `CreateThread(..., CREATE_SUSPENDED, ...)` fails, `DeviceServiceEntry()` frees the already...
๐จ CVE-2026-91958
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
๐@cveNotify
FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.
๐@cveNotify
GitHub
Unbounded `MonitorIds[0]` used as an array index in X11 monitor selection
## Summary
A `.rdp` connection file can put any 32-bit value in `selectedmonitors`. The value lands in `FreeRDP_MonitorIds` with no range check, and `xf_detect_monitors()` later uses `MonitorIds...
A `.rdp` connection file can put any 32-bit value in `selectedmonitors`. The value lands in `FreeRDP_MonitorIds` with no range check, and `xf_detect_monitors()` later uses `MonitorIds...
๐จ CVE-2026-91959
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
๐@cveNotify
FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.
๐@cveNotify
GitHub
`rts_read_result()` length-checks 2 bytes and then reads 4 โ a truncated BIND_ACK result list aborts any client using the RPC gatewayโฆ
**Affected:**
| version | status |
| --- | --- |
| master `9415f2d11e4cbc4e25d3d9fd0c4271e2e05d5c58` (`libfreerdp3.so.3.30.1`) | affected; default configuration โ `-DCMAKE_BUILD_TYPE=Release`,...
| version | status |
| --- | --- |
| master `9415f2d11e4cbc4e25d3d9fd0c4271e2e05d5c58` (`libfreerdp3.so.3.30.1`) | affected; default configuration โ `-DCMAKE_BUILD_TYPE=Release`,...
๐จ CVE-2026-91960
FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.
๐@cveNotify
FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to trigger integer wraparound, resulting in a double free that crashes the FreeRDP client during connection.
๐@cveNotify
GitHub
`Stream_EnsureCapacity` still overflows to `new_capacity == 0` after the CVE-2026-27951 fix โ `realloc(p, 0)` abandons a danglingโฆ
**Affected:**
| version | status |
| --- | --- |
| master `9415f2d11e4c` (3.30.1) | affected; our own `cmake -DCMAKE_BUILD_TYPE=Release`, no sanitizer |
| 3.30.0 (Arch Linux `freerdp 2:3.30.0...
| version | status |
| --- | --- |
| master `9415f2d11e4c` (3.30.1) | affected; our own `cmake -DCMAKE_BUILD_TYPE=Release`, no sanitizer |
| 3.30.0 (Arch Linux `freerdp 2:3.30.0...
๐จ CVE-2026-76781
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
๐@cveNotify
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).
๐@cveNotify
๐จ CVE-2026-93972
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
๐@cveNotify
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
๐@cveNotify
GitHub
sourcecodester Online Reviewer Management System using PHP with Source Code V1.0 /reviewer_0/admins/assessments/course/btn_fuโฆ
sourcecodester Online Reviewer Management System using PHP with Source Code V1.0 /reviewer_0/admins/assessments/course/btn_functions.php?action=remove&courseID=7 SQL injection NAME OF AFFECTED ...
๐จ CVE-2026-93977
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
๐@cveNotify
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
๐@cveNotify
๐จ CVE-2026-94104
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.
๐@cveNotify
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.
๐@cveNotify
GitHub
GitHub - nivocart/nivocart: NivoCart, advanced shopping cart software solution.
NivoCart, advanced shopping cart software solution. - nivocart/nivocart
๐จ CVE-2026-94109
openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.
๐@cveNotify
openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.
๐@cveNotify
blog.evan.lat
deserialization as a service for a bunch of australian unis (CVE-2026-94109, CVE-2026-67615)
SUMMARY: an authenticated deserialization vuln in openEQUELLA allows an attacker to inject a SignedObject payload, unwrap the SignedObject, create an...
๐จ CVE-2026-16302
The Spectra Legacy โ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
๐@cveNotify
The Spectra Legacy โ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option through the uagb_blocks_info object without a capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including raw Instagram Graph API access tokens configured by an administrator. Exploitation requires the Spectra Pro plugin to be active with a linked Instagram account.
๐@cveNotify
๐จ CVE-2026-19532
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal.
This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.
๐@cveNotify
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal.
This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.
๐@cveNotify
siberguvenlik.gov.tr
T.C. Siber Gรผvenlik Baลkanlฤฑฤฤฑ
Tรผrkiye Cumhuriyeti Cumhurbaลkanlฤฑฤฤฑ Siber Gรผvenlik Baลkanlฤฑฤฤฑ resmi web sitesi.
๐จ CVE-2026-3253
The MailerLite โ Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms.
๐@cveNotify
The MailerLite โ Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms.
๐@cveNotify
๐จ CVE-2026-4806
The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings.
๐@cveNotify
The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings.
๐@cveNotify