Improper Validation of Integrity Check Value Affecting neutrinolabs/xrdp package, versions [,0.10.6)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NEUTRINOLABSXRDP-16299813
  • published26 Apr 2026
  • disclosed17 Apr 2026
  • creditexploitintel

Introduced: 17 Apr 2026

CVE-2026-32105  (opens in a new tab)
CWE-354  (opens in a new tab)

How to fix?

Upgrade neutrinolabs/xrdp to version 0.10.6 or higher.

Overview

Affected versions of this package are vulnerable to Improper Validation of Integrity Check Value in the dataSignature verification process. An attacker can alter encrypted RDP traffic without detection by performing a man-in-the-middle attack in non-TLS mode. This is only exploitable if the "Classic RDP Security" layer is used and TLS is not enforced.

Workaround

This vulnerability can be mitigated by configuring the system to enforce TLS security (security_layer=tls) in the configuration file.

CVSS Base Scores

version 4.0
version 3.1