FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated authlength field read from the network triggers a WINPRASSERT() failure in rtsreadauthverifiernochecks(), causing any FreeRDP client connecting through a malicious RDP Gateway to crash with SIGABRT. This is a pre-authentication denial of service affecting all FreeRDP clients using RPC-over-HTTP gateway transport. The assertion is active in default release builds (WITHVERBOSEWINPRASSERT=ON). This issue has been patched in version 3.24.2.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.24.2"
}
],
"source": "AFFECTED_FIELD"
}
],
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-617"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33952.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33952.json"
[
{
"deprecated": false,
"id": "CVE-2026-33952-79be3e73",
"source": "https://github.com/freerdp/freerdp/commit/4ac0b6467d371a1ad47c1f751c5b305e4c068adb",
"signature_type": "Function",
"digest": {
"length": 1180.0,
"function_hash": "59804165366292898073712220204439900962"
},
"signature_version": "v1",
"target": {
"file": "libfreerdp/core/gateway/rts.c",
"function": "rts_read_common_pdu_header"
}
},
{
"deprecated": false,
"id": "CVE-2026-33952-e5bbbc13",
"source": "https://github.com/freerdp/freerdp/commit/4ac0b6467d371a1ad47c1f751c5b305e4c068adb",
"signature_type": "Line",
"digest": {
"line_hashes": [
"231781365805317644818485254324437838217",
"82578642349437193098999506985254534394",
"66587847882168671760024679617306138172",
"331941691904885503869454691564974165656"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "libfreerdp/core/gateway/rts.c"
}
}
]
"2026-08-12T15:33:31Z"