{"id":"CVE-2026-91947","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-91947","summary":"FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated…","details":"FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.","published":"2026-09-15T16:17:48.353","modified":"2026-09-15T16:17:48.353","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/freerdp-server-before-3.31.0-use-after-free-via-drdynvc"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T16:17:48.353"}}