CVE-2026-91958

Source
https://cve.org/CVERecord?id=CVE-2026-91958
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91958.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91958
Aliases
  • GHSA-23pf-q83q-x45r
Downstream
Published
2026-09-15T15:18:13Z
Modified
2026-09-17T03:47:20Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index
Details

FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap read and write operations when opened in xfreerdp.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91958.json"
}
References

Affected packages

Git / github.com/freerdp/freerdp

Affected ranges

Type
GIT
Repo
https://github.com/freerdp/freerdp
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.11.0"
        },
        {
            "fixed": "3.31.0"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91958.json"