Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-67297

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

EPSS

Процентиль: 27%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
debian
2 дня назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when pr ...

CVSS3: 7.5
github
2 дня назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

EPSS

Процентиль: 27%
0.00343
Низкий

7.5 High

CVSS3

Дефекты

CWE-770