FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-67289 is a critical header injection vulnerability in FreeRDP versions 3.28.0 and earlier that allows malicious RDP servers to inject arbitrary HTTP headers and control characters through the TargetNetAddress field during server redirection. When a FreeRDP client connects through an HTTP proxy, the unvalidated redirection data is directly written into the CONNECT request line and Host header, enabling attackers to manipulate proxy behavior, bypass security controls, or redirect connections to unintended destinations. This vulnerability affects all users of vulnerable FreeRDP versions who connect through HTTP proxies—a common scenario in enterprise environments where proxy infrastructure mediates outbound connections.
While CVE-2026-67289 lacks direct MITRE ATT&CK technique mapping, Casky's Claude-powered analysis engine would detect the underlying attack patterns through behavioral anomaly detection across proxy traffic and protocol manipulation tactics. Practitioners using Casky would observe findings related to HTTP protocol abuse, suspicious header modifications in proxy CONNECT requests, and anomalous RDP redirection sequences that deviate from expected client-server communication patterns. Extended reasoning across Casky's 754 security skills would correlate malformed CRLF injection attempts with proxy evasion behaviors, helping security teams identify exploitation attempts even before official MITRE mappings are established, enabling faster threat detection and containment.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-67289. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation