Bug 2510004 (CVE-2026-67289)
| Summary: | CVE-2026-67289 FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in FreeRDP. A malicious or compromised Remote Desktop Protocol (RDP) server can exploit this vulnerability to inject arbitrary headers or requests into an HTTP proxy CONNECT request. This occurs because FreeRDP does not properly validate control characters in the server-controlled RDP redirection TargetNetAddress field, which is then used without filtering. This injection could allow an attacker to manipulate the proxy's behavior or bypass certain network security policies.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2510446, 2510444, 2510448 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-01 13:02:50 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:54486 https://access.redhat.com/errata/RHSA-2026:54486 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:54485 https://access.redhat.com/errata/RHSA-2026:54485 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:54487 https://access.redhat.com/errata/RHSA-2026:54487 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:58711 https://access.redhat.com/errata/RHSA-2026:58711 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:58712 https://access.redhat.com/errata/RHSA-2026:58712 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:58710 https://access.redhat.com/errata/RHSA-2026:58710 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:58713 https://access.redhat.com/errata/RHSA-2026:58713 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:60173 https://access.redhat.com/errata/RHSA-2026:60173 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:61250 https://access.redhat.com/errata/RHSA-2026:61250 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:61251 https://access.redhat.com/errata/RHSA-2026:61251 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:62401 https://access.redhat.com/errata/RHSA-2026:62401 |