CVE Explorer
CVE-2026-32623
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the NeutrinoRDP module. When proxying RDP sessions from xrdp to another server, the module fails to properly validate the size of reassembled fragmented virtual channel data against its allocated memory buffer. A malicious downstream RDP server (or an attacker capable of performing a Man-in-the-Middle attack) could exploit this flaw to cause memory corruption, potentially leading to a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"xrdp","vendor":"neutrinolabs","versions":[{"status":"affected","version":"< 0.10.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d80b190a2ccac2ab3f3e8bd8225bbfc3bad2952004f980062417e9bf2163ac25 · sha256:1acd77a6b9b60956… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d80b190a2ccac2ab3f3e8bd8225bbfc3bad2952004f980062417e9bf2163ac25 · sha256:1acd77a6b9b60956… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-122","description":"CWE-122: Heap-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d80b190a2ccac2ab3f3e8bd8225bbfc3bad2952004f980062417e9bf2163ac25 · sha256:1acd77a6b9b60956… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6","tags":["x_refsource_MISC"],"url":"https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d80b190a2ccac2ab3f3e8bd8225bbfc3bad2952004f980062417e9bf2163ac25 · sha256:1acd77a6b9b60956… · /containers/cna/references/1
{"name":"https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-phw3-qp59-x2v4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-phw3-qp59-x2v4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d80b190a2ccac2ab3f3e8bd8225bbfc3bad2952004f980062417e9bf2163ac25 · sha256:1acd77a6b9b60956… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.