CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67292

mediumCVSS 6.5covered by 1 sourcefirst seen 2026-08-01
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).

⚡ Watch CVE-2026-67292

Get an email if CVE-2026-67292 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-67292

CVE.org record

Embed the live status

CVE-2026-67292 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67292 status](https://www.csirts.com/badge/CVE-2026-67292)](https://www.csirts.com/cve/CVE-2026-67292)