Freerdp · Freerdp · CVE-2026-91959
**Name of the Vulnerable Software and Affected Versions**
FreeRDP versions prior to 3.31.0
**Description**
A buffer over-read occurs in the `rts read result()` function within the RPC gateway transport parser. An attacker can trigger an out-of-bounds read, leading to a process abort, by sending a malicious BIND ACK PDU (Protocol Data Unit) containing a truncated result entry.
**Recommendations**
Update to version 3.31.0 or later.