CVE-2026-91949

NameCVE-2026-91949
DescriptionFreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freerdp2 (PTS)bookworm2.11.7+dfsg1-6~deb12u1fixed
freerdp3 (PTS)trixie3.15.0+dfsg-2.1+deb13u3vulnerable
forky, sid3.32.1+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freerdp2source(unstable)(not affected)
freerdp3source(unstable)3.31.0+dfsg-1

Notes

- freerdp2 <not-affected> (Only affects 3.0 and later)
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6
https://www.openwall.com/lists/oss-security/2026/09/01/2

Search for package or bug name: Reporting problems