CVE-2026-44178
xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
| CWE | CWE-122 |
| Vendor | neutrinolabs |
| Product | xrdp |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Get instant alerts for neutrinolabs xrdp
Be the first to know when new high vulnerabilities affecting neutrinolabs xrdp are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H