Freerdp · Freerdp · CVE-2026-91961
**Name of the Vulnerable Software and Affected Versions**
FreeRDP versions prior to 3.31.0
**Description**
A denial-of-service issue exists in the URBDRC control-transfer request path. The software fails to validate the `OutputBufferSize` variable before forwarding it to the libusb backend. A malicious RDP server can send a control-transfer request with `OutputBufferSize` set to 65536, which triggers an assertion that terminates the client process.
**Recommendations**
Update to version 3.31.0 or later.