# 2026-09-23 Version 3.32.0

New release with many user visible goodies for all of you.
There have also been *lots* of issues addressed to harden against protocol violations/exploits,
thanks to all the people doing in depth code reviews and security reports.

* [proxy] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX
* [proxy] add configuration options for target certificate policy.
  NOTE: This changes default behavior from accept unless denied to deny unless accepted!
        Requires an update of your proxy configuration file if you rely on this.
* [SDL,xfreerdp] seamless Entra/Azure integration on linux (with helper binaries)
* [beta] Basic SDL client RAILS support for X11/wayland (other platforms currently
  lack some features / platform integration code, as we still need some native hooks)
* [RDPECAM] stops camera streams now when the remote no longer requests frames.
  (no more camera LED after closing the windows application accessing it)
* [RDPEWA] support user verification in addition to / instead of pin
* [RDPEUSB] properly map interface index to interface numbers
  (more devices should work now)
* [android] updated touch pointer
* [wlfreerdp] shortcut inhibit release on mouse leave window
* [xfreerdp] rails improvements, hopefully no longer shrinking windows
* Full support for [MS-RDPBCGR] 2.2.10.2 Early User Authorization Result PDU,
  so now you get a error message if a user is not allowed to log in instead of
  a network failed message. (Authentication /sec:ext or PROTOCOL_HYBRID_EX)
* [shadow] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX
* [gateway] split HTTP timeout from TCP connect timeout
* [ffmpeg] support generic hardware accelerated encoding/decoding, replacing the
  old VAAPI only implementation. (still experimental as there are often driver issues)

## CVE

Note: Advisories will be published days/weeks after the release, so links are 404
      until then.

* by Opensec Intelligence
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xq87-9rrm-6wqw
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3rvr-qvx8-rj23
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pvgq-84w2-93ph
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xm53-352c-57jw
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mq5-xh88-9v62
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mqxv-c882-m8w9
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q6pp-28g8-xqjc
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jgw9-wqvx-j495
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5cgr-vmp8-fmvj
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m7g5-gw57-cwcr
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjxv-5j98-cqx4
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pw4j-ff39-9vjm
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-87v8-2gwr-ww9j
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h7fx-22wv-4cg8
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-996j-34w6-5hgm
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-52xc-5973-w5vv
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qjwp-c855-hc69
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4ww8-3vqm-jgcf
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-96rv-gf42-7wq9
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9qr4-rgq4-jfp8
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cq4m-gwc5-w8rc
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q9p9-j22r-577p
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2jfv-j3wx-5cg4
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-g8jw-gv54-r94p
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7vfc-chg9-q5r8
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f46f-pxh9-w2rh
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pg3f-chj4-mrw6
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f526-rq4j-5ch8
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8rpr-jjjg-5qv6
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cmgx-558f-vh67
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m998-cvfm-9444
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-99p4-8j24-wvj4
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-97pf-pwp3-2wrv
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-27m7-gwhh-6hhf
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qpfh-m9w6-xf2x
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q56j-jjh6-38jf
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f554-v4xw-5j39
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-chh2-527f-x255
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xf45-j844-588v
* by @DavidKorczynski
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qq23-mqmv-pc65
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jhxw-3hj9-9hqh
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h44v-39x6-9xvg
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6vjv-4hm3-6698
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c3rh-2hv6-7hf2
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp2r-gm4v-wvq2
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-gvq8-v2fm-ffxv
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jhv5-m83m-hxhq
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-grvc-qhhp-7h6m
* by @programmervuln
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-26cc-wjh8-hjw6
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-945c-qq5h-jqwp
* by @HAN-BAMBO
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-93g7-296p-j77j
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6rj3-rf6g-3vw5
* by @kimaiden1984-boop
  * https://github.com/FreeRDP/FreeRDP/security/advisories/HSA-wf3x-658c-52m5
  * https://github.com/FreeRDP/FreeRDP/security/advisories/HSA-2hhg-8xx6-v73w
* by @jimaf
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-g4wg-67xq-8q53
* by @thawkahant
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72qv-gcph-rfwf
* by @smaeljaish771
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vqxm-9w7c-hvvx
* by @D7EAD
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hxw3-57rq-3v4m
* by @manus-use
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f4pf-pgp4-f2r3
* by @router0mail
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4mpr-hmqx-83q8
* by mail
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v7-9jp5-wqj2
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g

## What's Changed
* Various WinPR addings (#13311)
* [cache] improve cache_resize (#13317)
* OSS-Fuzz: Add fuzzer for Smartcard Operations (#13323)
* [codec,fdk] ignore decoder errors (#13324)
* [codec,h264] overallocate decoder buffers (#13326)
* [warnings,s(n)printf] fix missing return value checks (#13325)
* [client,common] fix TestClientRdpFile (#13333)
* [winpr,library] fix mac os GetModuleFileNameA (#13337)
* [channels,pulse] survive hot-removal of the active audio device (#13334)
* [client,common] map gatewaycredentialssource from rdp files (#13330)
* Warn fix pointer (#13341)
* Relax order checks (#13343)
* OSS-Fuzz: Add new fuzzer targets Client Rdp File processing (#13344)
* [channels,urbdrc] report the negotiated device speed (#13345)
* [client,x11] fix clipboard atom evaluation (#13347)
* [client,x11] use correct count to iterate atoms (#13349)
* licensing checks & gfx surface format hacks (#13351)
* [channels,urbdrc] give the device speed a type (#13352)
* [core,gateway] bound ARM gateway responses by their own timeout, not TcpConnectTimeout (#13327)
* [codec,h264] configure ffmpeg via env variables (#13316)
* [winpr,image] honor bfOffBits when parsing bitmaps (#13350)
* [cache,pointer] explicitly cast to void* (#13353)
* Ci warning fixes (#13354)
* [client,cmdline] honor explicitly disabled multimon and smart-sizing (#13331)
* [client,common] eliminate dead code (#13357)
* [alignment] add WINPR_PACKED_ALIGN_CAST (#13355)
* Silence cast function type (#13358)
* [winpr,info] add warning log for winpr debug options (#13359)
* [winpr,align] more warnings on unsupported configurations (#13360)
* [winpr,ncrypt] add idLen checks (#13361)
* Msvc unaligned (#13362)
* Fuzzer fixes (#13363)
* Channels nodiscard (#13366)
* l10n: add Swedish Android localization (#13365)
* various cleanups and fixes (#13368)
* [client,sdl] handle Windows E0 36 as right shift (#13369)
* [client, ios] iOS client build fix (#13083)
* Cleanups september (#13370)
* [winpr,library] implement GetModuleFileNameA on OpenBSD with getexecpath() (#13335)
* [cmake] fix building on OpenBSD (#13380)
* [winpr,cast] fix parentheses (#13379)
* [winpr,library] move FreeBSD GetModuleFileNameA into function (#13382)
* [winpr,cast] add PPC and s390x to supported (#13383)
* Pulse detect (#13384)
* [codec,dsp] fix compiler warnings (#13385)
* [client,common] fix POSIX command-line status options (#13372)
* [codec,dsp] fix variable init for soxr (#13386)
* [codec,h264] fix broken MediaFoundation decoder build (#13389)
* [ci,windows] enable WITH_MEDIA_FOUNDATION (#13390)
* Scard checks (#13395)
* [client,x11] preserve requested size for ordinary windows (#13373)
* [client,x11] honor decorations for RemoteApp windows (#13393)
* [client,x11] release pointer grab when RemoteApp loses focus (#13392)
* Ndr length checks (#13399)
* [channels,rdpear] fix missing NULL check (#13400)
* [client,android] horizontal scroll and middle click (#13401)
* [client,android] add touchpad two-finger scroll (#13402)
* [core,transport] abort write hard if it fails (#13404)
* [core,rdstls] Fix version validation macro (#13406)
* fix GDI handle leaks in wf_gdi_mem3blet (#13403)
* Geometry checks (#13407)
* [core,sdl] externalize the AAD credentials in an external process (#13340)
* Winpr wcschr (#13408)
* Tighten checks (#13410)
* [channel,urbdrc] fix func_claim_all_interface, mark [[nodiscard]] (#13411)
* [utils,http] enable host verification (#13412)
* Unaligned eliminate (some) (#13405)
* [packaging,all] enable WITH_XDG_AAD_AUTH_HELPER (#13413)
* [core,rdstls] accept matching autoreconnect cookies (#13414)
* [core,gateway] do not require a final auth token (#13418)
* [rdpecam,v4l] release capture when sample requests drain (#13417)
* Stream utf16 and persistent cache fixes (#13421)
* Fix usage of interface index as an interface number (#13419)
* [core,security] add ExtSecurity to all clients and server (#13415)
* [uwac,client] fix invisible Wayland cursor and stuck shortcut inhibitor (#13424)
* [channels,audin] fix mac/ios input validation (#13423)
* [client,x11] fix RemoteApp drop-down menus and dialog window size feedback loop (#13422)
* [client,sdl] RemoteApp (RAIL) support for the SDL3 client (#13133)
* [client,sdl] generate xdg glue code without warnings (#13425)
* [ci,packaging] fix deb control dependencies (#13426)
* Proxy drdynvc (#13434)
* [client,sdl] add new events from SDL 3.3.2 and newer (#13435)
* set_termianl_nonblock -> set_terminal_nonblock (#13428)
* Oauth2 state tracking (#13433)
* [winpr,utils] SAM parser: zero memory before free (#13436)
* Client common context checks (#13438)
* no Password: prompt and don't mess with tty if stdin is a pipe (#13437)
* [client,common] fix inverted assert (#13439)
* [channels,rdpdr] add a workaround for windows server 2003 and XP (#13445)
* [client,common] implement common client AAD helper (#13441)
* Kbd mapping config (#13444)
* [client,common] unify aad token navigation code (#13446)
* [client,common] fix arguments order (#13447)
* Tsg and cleanups (#13448)
* Harden (#13451)
* sysinfo.c: fix macOS cpu macros (#13452)
* reject unterminated applicationId in rail get appid resp (#13453)
* Harden more (#13456)
* SDL3: fix typo (#13462)
* [core,server] sanitize KeyboardType received from clients (#13461)
* [memory] prefer winpr_aligned_calloc (#13466)
* [server,proxy] add TargetCertPolicy config option (#13463)
* OSS-Fuzz: Disable libpulse manually for oss-fuzz build (#13465)
* Harden again (#13464)
* [client,x11] fix RAIL window repaint volume (invalid region never reset, updates for unmapped windows) (#13459)
* Warn cleanup (#13467)
* Warn cleanup (#13467)
* Refinements (#13468)
* Refinements some more (#13469)
* [codec,dsp] fix fdk-aac encoding (#13470)
* Cleanups (#13471)
* [core,gateway] never pass NULL to websocket_reply_close (#13474)
* [core,fastpath] add fastpath errors to relax-order-checks (#13476)

## New Contributors
* @shakeelosmani made their first contribution in (#13334)
* @sjtrotter made their first contribution in (#13330)
* @huanzhang12 made their first contribution in (#13350)
* @yeager made their first contribution in (#13365)
* @Ohyunj made their first contribution in (#13403)
* @yerbolgmailcom made their first contribution in (#13417)
* @slavaandrejev made their first contribution in (#13419)
* @berkeleyinc made their first contribution in (#13424)
* @unicon221 made their first contribution in (#13422)
* @barracuda156 made their first contribution in (#13452)
* @gaardiolor made their first contribution in (#13461)
* @arthgirard made their first contribution in (#13459)

For a complete and detailed change log since the last release run:
git log 3.32.0...3.31.1

# 2026-09-02 Version 3.31.1

After the last huge CVE and security fix releases finally a simple papercut fix release.

## Most notable user visible changes:
* xfreerdp image clipboard now better handles conversion of host images to bitmap
  (CF_DIB the default windows exchange format)
* improved keyboard mapping for sdl-freerdp (some more exotic keys are properly mapped now)
* xfreerdp RAILS: better transparency support with windows 11
* Fix C23 macro definitions for GCC

## What's Changed
* create alpha capable GFX surfaces for XRGB_8888 (#13280)
* Cleanups (#13282)
* [client,sdl3] fix flickering on screens with DPI != 1.0 (#13278)
* [debug,logs] fix warnings and errors WITH_DEBUG_ALL (#13283)
* Fix the settings of FreeRDP_UnicodeInput bug (#13287)
* only use AV_PIX_FMT_D3D12 in ffmpeg >=7 (#13286)
* [winpr,handles] allow to Close a HANDLE listed in PROC_THREAD_ATTRIBUTE_HANDLE_LIST (#13284)
* [cmake] proper Threads::Threads detection (#13288)
* X11 image clip (#13289)
* [client, mac] fix: build error undeclared 'nullptr' in Keyboard.m (#13290)
* [codec,h264] overallocate YUV buffer (#13291)
* build(test): only build JSON-dependent test when JSON is available (#13293)
* [codec,h264] fix missing version guards (#13294)
* [ci,qa] enable all debug options for static build (#13295)
* feat: [client, mac, sdl3] support jp YEN/RO/EISUU/KANA keys (#13299)
* [winpr,json] read JSON files in binary mode (#13298)
* [client,sdl] map media pause scancodes (#13297)
* [core,test] do not link winpr-tools when WITH_WINPR_TOOLS=OFF (#13303)
* [channels,rdpear] return krb5 output buffer only after the call succeeds (#13307)
* Media foundation fixes (#13308)
* Winpr tools optional (#13309)
* [c23] fix gcc compatibility issues (#13310)
* [winpr,clipboard] honor DIB header size in BMP offsets (#13304)
* [core,capabilities] apply HasQoeEvent from src, not settings (#13313)
* [server,shadow] better logging for cert/key related problems (#13314)
* [codec,h264] log vaapi driver vendor (#13315)
* [server,shadow] better logging for cert/key related problems (#13314)
* [codec,h264] log vaapi driver vendor (#13315)
* Proxy compat (#13319)

## New Contributors
* @fundawang made their first contribution in (#13286)
* @cawcaw2023 made their first contribution in (#13290)
* @MeGaurav4 made their first contribution in (#13293)
* @SebastienGllmt made their first contribution in (#13298)
* @Lishkinfeld made their first contribution in (#13303)
* @4sh0u0 made their first contribution in (#13313)

For a complete and detailed change log since the last release run:
git log 3.31.1...3.31.0

# 2026-08-26 Version 3.31.0

Huge bugfix and security release.

We've received quite a number of smaller and bigger bugfixes and security reports
that have been addressed with this release.
Most important user facing change is a optimization of the YUV decoder which
will result in faster client graphics for AVC/H264 sessions

IMPORTANT: Distributors, please update ASAP, there are severe issues being
           addressed with this release

# CVE
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c5gr-hmqp-pwj4
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h5w2-q35j-443h
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m85m-3qxv-63h5
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r9pv-ffph-6gg6
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ffjr-p229-hpch
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4464-r7qj-pgrx
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hg4r-vv53-vwf8
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-57h7-vw2f-2f9x
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72q
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j5mq-3349-gwmm
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pj8w-fh79-f438
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vccg-35r5-8jrf
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-w9qg-g24r-77f6
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f5p6-88mh-59vg
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r

## What's Changed
* Warnings removed (#13076)
* [codec,h264] support more hardware decoders (#13078)
* [crypto] gracefully handle failed BIO/SSL creation error (#13080)
* Ntlm custom (#13079)
* Sspi tests (#13082)
* [winpr,sspi] unify NTLM memory handling (#13085)
* [codec,yuv] bound avc444v2 chroma combine to decoded frame width (#13084)
* [client,common] use configured AAD authority for sso-mib (#13088)
* [channels,rail] fix server side channel tracker (#13087)
* Session info (#13089)
* [winpr,ntlm] limit data copy to smaller entity (#13090)
* [core,message] clone notify icon state order for async update (#13092)
* [mf, mediacodec] fix h264 typo (#13101)
* Fix for #13102 (#13108)
* [client,android] send clipboard format list response (#13104)
* [gdi] bound hatched brush pattern index in gdi_patblt (#13111)
* [winpr,ntlm] require 16 byte signature buffer before access (#13119)
* [client,sdl] stop drawing when update queue is empty, fixes high CPU (#13121)
* cmake: add C++ filesystem detection module (#13124)
* [winpr] add OpenBSD support for thread ID (#13154)
* winpr: fix missing FreeLibrary/GetProcAddress declarations on Cygwin (#13138)
* winpr: fix Cygwin GetModuleHandleW/TlsAlloc collisions under static linking (#13140)
* collected bug fixes (#13160)
* [core,server] parse drdynvc PDU through a substream (#13162)
* [client,common] fix audio-mode documentation (#13161)
* [client,android] replace deprecated KeyboardView (#13145)
* [urbdrc] Fix TRANSFER_OUT completion framing (#13129)
* [client,x11] abort if invalid monitor index was supplied. (#13163)
* [codec,dsp] reset buffered samples on close (#13165)
* Avc444 chroma (#13164)
* [core,nla] report early user auth denial as ACCESS_DENIED (#13166)
* [server,proxy] free peer while peer_list locked (#13159)
* Hotplug (#13167)
* uwac: don't try to use O_TMPFILE on OpenBSD (#13172)
* [winpr,string] fix building on OpenBSD (#13171)
* [channels,urbdrc] report the real IOCONTROL_COMPLETION output size (#13170)
* [codec,openh264] handle nonzero result codes (#13177)
* [codec,h264] fix offset region change detection (#13176)
* [winpr,sspi] fix server-side SPNEGO mechanism fallback (#13169)
* [cmake] build fixes for OpenBSD (#13173)
* [winpr,sysinfo] use CLOCK_MONOTONIC as a fallback (#13178)
* [channels,rdpdr] fix missing NULL check (#13180)
* [libfreerdp,crypto] add compilation opt-in TLS AEAD data limit with RFC 8446 threshold (#13152)
* [winpr,sysinfo] use sysctlbyname for OSX and iOS (#13179)
* [settings] allow null arg in freerdp_addin_argv_new (#13117)
* [client,common] url decode file paths (#13182)
* [codec,yuv] make tile size compile time configurable (#13181)
* [cache,pointer] cleanup and more logging (#13183)
* [winpr,sspi] dispatch by package index instead of a mixed-width name (#13136)
* Fix RAIL maximize normalization on Cinnamon (#13147)
* [core,gateway] bound tsg authorize tunnel response to received length (#13186)
* [channels,rdpdr] don't free() mntbuf in handle_platform_mounts_bsd() (#13187)
* [winpr,sysinfo] use sysconf _SC_NPROCESSORS_ONLN on *BSD (#13174)
* [core,nego] report why security negotiation failed (#13185)
* uwac: only use O_TMPFILE if it exists (#13191)
* [cmake] fix Sndio bits and not limit support to just OpenBSD (#13188)
* [winpr,cmake] fixes for epollshim headers / function detection (#13190)
* [channels,rdpsnd] fix sndio compile warnings (#13193)
* [warnings] remove unused functions and variables (#13184)
* [cache,glyph] clean up code, relax order checks (#13194)
* uwac: disable the SHM_ANON support on DragonFlyBSD (#13195)
* [libfreerdp] fix detection of FFmpeg (#13197)
* Cache recreate on deacviate/reactivate, stream checks (#13196)
* [channels,smartcard] prevent duplicate cleanup (#13198)
* [channel,urbdrc] check func_get_ep_desc for validity (#13199)
* [cache,pointer] reset pointer before cache free (#13200)
* [cmake,epollshim] use PkgConfig::EPOLLSHIM target (#13203)
* [client,sdl] fix scaled drawing (#13205)
* [cmake] link explicitly PUBLIC/PRIVATE/INTERFACE (#13206)
* [client,core] add gcc validity checks (#13207)
* [crypto,x509] relax object_string checks (#13209)
* More Checks... (#13212)
* [codec,av1] use dav1d for AV1 decoding (#13211)
* [scard,pack] fix NDR pointer validation for empty card handles (#13208)
* Pkg config imported (#13213)
* [utils,test] fix generated test data (#13214)
* [channels,rail] fix NULL deref race on server channel start (#13216)
* [channels,cliprdr] fix long format list parse (#13217)
* [scard,pack] remove incorrect stream length checks in unpack functions (#13215)
* [client,x11] clear errno before keyboard pipe read (#13220)
* Fix use-after-free of the printer driver singleton (#13221)
* [codec,yuv] fix pool_decode_rect loop variable reuse (#13223)
* [channels,cliprdr] fix server-side format-list negotiation bugs (#13225)
* fix use-after-free when winpr_aligned_recalloc fails (#13224)
* [channel,urbdrc] add missing check (#13228)
* [utils,rdpdr] force 64bit arithmetic in rdpdr_dump_packet (#13229)
* Sdl image clipboard (#13230)
* [codec,fdk] revert AACENC_GRANULE_LENGTH, (#13231)
* [winpr,sspi] add custom extensions (#13222)
* Sspi cleanup (#13233)
* Canonicalize paths (#13175)
* Timeout (#13234)
* Rail workarea updates (#13238)
* OSS-Fuzz: Disable SNDIO manually for oss-fuzz build (#13240)
* Dos xattr (#13239)
* Test fuzz server (#13241)
* [winpr,cmake] guard CheckSourceCompiles (#13242)
* [core] fix memory leak in TestFuzzServerSeedGen (#13245)
* [core,connection] abort after PROTOCOL_FAILED_NEGO (#13250)
* Safe zero (#13248)
* [gdi] document cache requirement for gdi_init (#13249)
* [core,server] lock dynamic channel list while parsing (#13251)
* [cmake,yuv] fix detection without pkg-config (#13252)
* [client,x11] fix /gdi:hw surface creation (#13255)
* winpr/sspi/negotiate: NULL check sub credentials accepting context (#13254)
* [utils,scard] validate ReaderState_Return on use (#13256)
* Fuzzer improvements (#13257)
* [winpr] implement inheritable handles in CreateProcess (#13246)
* Warning fixes (#13258)
* [doxygen] add missing @since version tags (#13259)
* Cross fixes (#13260)
* [winpr,path] fix mingw builds, link lowercase names (#13261)
* Relax check in window_state_order_clone (#13263)
* [core,test] ignore SIGPIPE in TestFuzzServerSeedGen (#13265)
* Fix utf-8 encoding of LS and PS in winpr_str_has_newlines (#13262)
* Cross mingw fixes (#13264)
* [build,mingw] fix missing includes (#13268)
* [build,mingw] replace C++11 constructs (#13269)
* [client,x11] fix cliprdr infinite request loop (#13266)
* [winpr] fix TestThreadCreateProcess (#13273)
* Release cleanups (#13270, #13272, #13274, #13277)

## New Contributors
* @cordlandwehr made their first contribution in (#13080)
* @berylraven made their first contribution in (#13088)
* @tearfulDalvik made their first contribution in (#13101)
* @cizra made their first contribution in (#13121)
* @a5ehren made their first contribution in (#13124)
* @brad0 made their first contribution in (#13154)
* @robertschulze made their first contribution in (#13138)
* @uchouT made their first contribution in (#13129)
* @zx1991 made their first contribution in (#13177)
* @mjpowersjr made their first contribution in (#13169)
* @jclairembault made their first contribution in (#13152)
* @hamed7ir made their first contribution in (#13136)
* @Eneratos made their first contribution in (#13147)
* @ElCruncharino made their first contribution in (#13211)
* @maordadush made their first contribution in (#13216)
* @gornkv made their first contribution in (#13220)
* @eunho87 made their first contribution in (#13221)
* @jasonmli8 made their first contribution in (#13263)

For a complete and detailed change log since the last release run:
git log 3.31.0...3.30.0

# 2026-07-16 Version 3.30.0

Security and bugfix release.
Addresses a severe server side issue, update highly recommended.

## CVE
* Claude and Ada Logics
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m37j-jcr2-8gcc
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x

## What's Changed
* Logon info update (#13060)
* Websocket regression fix (#13064)
* Sdl clipbaord and bounds checks (#13065)
* [core,rdstls] improve version handling (#13066)
* [channels,drdynvc] fix channel unref on create request send failure (#13067)
* Audin checks (#13068)
* [channels,rdpsnd] tighten bounds checks (#13070)
* Pcap cleanup (#13071)

For a complete and detailed change log since the last release run:
git log 3.30.0...3.29.0

# 2026-07-14 Version 3.29.0

Security, bugfix and maintenance release.
We've received a very rigorous review since our last release by a couple of
security researchers, so this release contains quite a number of advisories.
An update is highly recommended.

## CVE and advisories
* Bin Luo, University of Electronic Science and Technology of China (UESTC).
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-43hh-p3vw-hfx3
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ph3q-f9w8-7jf3
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-whq8-c3v3-p8v8
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hgj8-g595-wfc6
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8v6m-2cmc-chx9
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5wr6-8m8j-3h7f
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-89c6-jjrw-96h4
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8xqm-wp3f-rfp9
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qmvw-52ph-q5pv
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-34hq-hwjw-q8v3
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-33gg-h66j-3697
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vxp3-7g6q-rq2w
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v89x-pc32-hqr7
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pfxq-3qmw-8vjx
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5
* @canomer
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x
* Reported by Team Atlanta
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8jj2-67pg-j6mg
* @HEXER365
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qrxx-7g3c-j6w3
* cbcs — found by Tencent Yunding Security Lab using agents
  * https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cj9v-h4hq-29jr

## What's Changed
* [client,sdl] Handle requested clipboard MIME formats (#13007)
* [client,x11] Fix RAIL HiDef window maximize (#13010)
* [channels,rdpecam] filter devices without supported formats (#13015)
* [codec,planar] fix input checks (#13016)
* [client] do not build wayland and windows (#13017)
* [client,windows] add server response size check (#13018)
* fix processImageName length check in rail get appid resp ex (#13020)
* [channels,rdpecam] add data validity checks (#13021)
* Scard alloc update reorder (#13022)
* H264 decoder surface dimension mismatch (#13024)
* [core,security] reject short server random in security_establish_keys (#13023)
* Async update (#13025)
* [core,rdstls] add endpoint FedAuth token authentication (#13026)
* Resource limits (#13027)
* Path checks (#13028)
* [emu,scard] require Lc of 2 for select-by-FID in vgids_ins_select (#13030)
* runtime hardening (#13032)
* H264 fix (#13036)
* [crypto,x509] improve hardening against embedded \0 (#13035)
* [core,rail] unify RAIL_UNICODE_STRING handling (#13039)
* [channels,rail] rail_server_handle_messages (#13037)
* [channels,rdpecam] fix reading of config descriptor (#13042)
* [codec,av1] bound decode output to decoded frame size (#13044)
* Bounds check fixes (#13043)
* [codec,av1] add region rects checks like with AVC modes (#13045)
* Ios fixes (#13029)
* Ios warn fixes (#13047)
* [utils,smartcard] exclude ndr padding from returned buffer length (#13046)
* Serial alloc checks (#13049)
* Android build fixes (#13050)
* [client,android] update build (#13051)

## New Contributors
* @kogekiplay made their first contribution in (#13007)

For a complete and detailed change log since the last release run:
git log 3.29.0...3.28.0

# 2026-07-06 Version 3.28.0

Feature and bugfix release.
* iOS client has been revived by @bho3538
* Android client build updates by @svncibrahim
* Windows client did get some updates by @zorjen122
* Server side smartcard API by @joantolo
* Improved client statistics interface, now also supports static channels
* Improved fuzzer and unit tests
* CMake preset support making it easier to create a working build configuration,
  see https://github.com/FreeRDP/FreeRDP/wiki/Compilation#presets

## CVE
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
  CVE-XXXX-XXXXX by Claude and Ada Logics
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9g22-w2gr-vcmp
  CVE-XXXX-XXXXX by Claude and Ada Logics
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f27x-frr8-j9hc
  CVE-XXXX-XXXXX by Claude and Ada Logics
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq
  CVE-XXXX-XXXXX by Claude and Ada Logics
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v64m-xxfw-hrv6
  CVE-XXXX-XXXXX by @rahulhoysala
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp
  CVE-2026-57158 by @hextheshadow
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47fr-jw86-c3fj
  CVE-2026-57157 by Owais Lone (Owais Lone)
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v5wf-j8j4-77h7
  CVE-2026-57156 by @HEXER365

## Security
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m

## What's Changed
* feat(client): Modernize iOS client. (iFreeRDP) (#12949)
* [client,ios] remove some deprecation warnings (#12981)
* Ios cmake (#12997)
* [client,ios] add openh264 build (#13003)
* [client,android] riscv64 support (#12923)
* [client,android] make release configurable (#12929)
* [client,android] allow overriding version name and code (#12931)
* [client,android] redesign touch pointer (#12946)
* [client,android] move external deps to own CMake file (#12992)
* Android build (#12917)
* [client,sdl] guard file clipboard (#12911)
* [client,sdl] Askpass (#12925)
* [client,sdl] throw a real exception instead of invalid bare throw (#12936)
* [client,sdl] run sdl_OnUserNotificationEventHandler on SDL thread (#12941)
* [client,sdl] fix mouse and touchpad natural scroll setting being ignored (#12967)
* fix(client/win) Reset scroll offset when hiding scrollbars (#7536) (#12939)
* feat(client/win): improve wfreerdp fullscreen floatbar controls (#12851)
* Channel stats (#12964)
* Statistics interface (#12968)
* [core,channels] add freerdp_static_client_channel_stat_free (#12966)
* Support RDPDR Device Control Responses (#12756)
* Wlog appender context (#12907)
* [winpr,image] bound unaligned bitmap read to declared image size (#12910)
* [codec,color] add empty checks for copy (#12912)
* Win credssp (#12913)
* Adjustments for building on Windows with MSVC (#12916)
* channel statistics and random gateway connection id (#12922)
* [channels,video] bound frame copy to current surface size (#12919)
* OSS-Fuzz: Add new fuzzers targets channels rail client (#12924)
* [utils,smartcard] validate cbAtr against rgbAtr size on unpack (#12928)
* [channels,rdpecam] fix device added notification parsing (#12930)
* [emu,scard] bound select-by-AID compare to GIDS AID length (#12933)
* Rails feature setting, xfreerdp kbd sync (#12927)
* [core,orders] fix inverted overflow guard in update_read_delta_points (#12938)
* [codec,mppc] add missing out of bounds check (#12942)
* [channels,tsmf] bound visible rect read in update_geometry_info (#12943)
* [channels,rdpecam] bound channel name read in device removed pdu (#12945)
* [core,tcp] improve connection failure logging (#12950)
* Warn fixes (#12951)
* [codec,planar] fix range check, abort early (#12952)
* [channels,rdpsnd,mac] recover audio after AVAudioEngine config change (#12958)
* [codec,planar] range-check before control byte read in plane rle (#12956)
* [channel,rail] fix tests and uninitialized variables (#12960)
* [channels,rdpdr] fix off-by-one scan length in rdpdr_read_ustring (#12961)
* [channels,remdesk] validate ctl pdu DataLength against received stream (#12955)
* [channels,rdpsnd] bound client format pdu length to UINT16 (#12962)
* Winpr harden parser checks (#12965)
* [winpr,file] bound '?' wildcard match to file name length (#12969)
* [channels,urbdrc] bound msusb descriptor reads to received length (#12971)
* [core,update] fix the calling convention for Windows x86 (#12973)
* [channels,drive] reject trailing '..' in contains_dotdot (#12974)
* OSS-Fuzz: Add new fuzzer targeets WinPRClipboard processing (#12976)
* Pr/12970 (#12975)
* Cliprdr and rdpsnd fixes (#12980)
* [channels,rail] fix order read/cleanup (#12979)
* [core,utils] skip AuthenticateEx for RDP/TSL/SMARTCARD_PIN/FIDO_PIN (#12978)
* replace NULL with nullptr (#12982)
* [channels,cliprdr] fix pdu-tracker leak (#12983)
* Fuzz fixes bmp (#12986)
* [core,gateway] fix const warning (#12987)
* [channels] bound dynamic channel message header to received length (#12988)
* cmake: add minimal preset for lightweight builds (#12989)
* Cleanup all (#12991)
* Range checks (#12993)
* Deprecations (#12994)
* [winpr,string] fix winpr_strnstr needle length (gateway SIGSEGV) (#12995)
* Bmp cache (#12999)
* [codec,dsp] ensure out capacity in opus encode (#13001)
* [winpr,string] match winpr_strnstr fallback to native strnstr (#13002)
* Smartcard fixes (#13009)
* [client,common] /smartcard-logon pass PEM directly (#13011)
* Correct UTF-8 to UTF-16 length (#13012)

## New Contributors
* @sldr made their first contribution in (#12916)
* @arthurscchan made their first contribution in (#12924)
* @TBX3D made their first contribution in (#12936)
* @rohitkuma1313 made their first contribution in (#12958)
* @kunimart made their first contribution in (#12967)
* @apocelipes made their first contribution in (#12973)
* @bho3538 made their first contribution in (#12949)
* @insaf021 made their first contribution in (#12988)
* @insaf021 made their first contribution in (#12988)
* @kapott made their first contribution in (#12995)

For a complete and detailed change log since the last release run:
git log 3.28.0...3.27.1

# 2026-06-17 Version 3.27.1

Bugfix/regression fix and android feature release
What did change:
* Fixed a regression with gateway connections
* Android client RDPECAM support
* Android client RAILS support

## CVE
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c495-h83v-3prp

## What's Changed
* [core,utils] fix guid2str (#12898)
* [client,android] Add RAIL/RemoteApp window support (#12887)
* Bitmap decode (#12899)
* [client,rdpecam,android] Add camera redirection support (#12894)
* [tools] make the generator create more clang-format friendly code (#12900)

For a complete and detailed change log since the last release run:
git log 3.27.1...3.27.0

# 2026-06-15 Version 3.27.0

A major feature / bugfix / cleanup release
What did change:
 * Password hash now uses a custom SSPI attribute on non windows systems
 * TLS seclevel now defaults to 2 and a minimum of TLS 1.2 is required.
   Client side the /tls:seclevel:<number> and /tls:enforce:<version> allow to override these.
   Server implementations can manually set these with rdpSettings::FreeRDP_TLSMinVersion and
   rdpSettings::FreeRDP_TlsSecLevel
   (See https://docs.openssl.org/3.0/man3/SSL_CTX_set_security_level/ for more details)
 * The RDP proxy got a fix which removed (unstable) structs from public headers. There are no
   known users of that (internal) API, but if you happen to be one please ping us.
 * Android client got some huge updates again (thank @svncibrahim)
 * Enhancements with Azure/Entra support: some (known but not officially documented) extensions
   have been added to make these connections more stable.
 * keyboard mapping
 * Allow RDPDR channel to pass additional arguments to the channel. Does not break existing behaviour
   but allows a channel supporting this to query the additional arguments for further use.
 * Fix some WinPR deprecation handling, add WITHOUT_WINPR_3x_DEPRECATED that allows building
   without any symbol deprecated during the stable 3 series
 * Some client side statistics logging API was added. By default prints a (trace) log at the
   end of a session, but it can be queried at any time for some connection details.

## CVE (Reported by SecBuddyF, Tencent Keen Lab)
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cx
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rp4-66mc-j9vx
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mmf-qh4f-frm6
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vx73-w5q6-7jqr
* https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5c5v-f78v-h2f6 (Reported by @f9j2n6nd8k-eng)

## What's Changed
* Call winpr_InitializeSSL in TestWinPRUtils/TestNTLM (#12746)
* [core,codec] Fix invalid overlap check (#12753)
* Improve clipboard massive files copying performance (#12743)
* [crypto,certificate] Honor BIO_should_retry (#12755)
* Unify PEM read routines (#12758)
* Build updates (#12772)
* Fix sdl3 clipboard for files (#12759)
* url: replace http://www.freerdp.com (#12781)
* Fuzz/analyzer fixes (#12791)
* [winpr,sspi] replace password-length heuristic with explicit hash (#12782)
* Claude suggestions (#12792)
* Disp check fix (#12795)
* [core,settings] Raise default security level (#12752)
* [clang,tidy] use workflow from ZedThree (#12806)
* Improve FIPS mode support (#12811)
* Lots of android specific improvements (#12773, #12777, #12783, #12784, #12785,
  #12786, #12787, #12788, #12807, #12812, #12815, #12818, #12819, #12820, #12822,
  #12748, #12750)
* [channels,audin] fix opensles error handling (#12751)
* [channels,audin] fix iOS and mac backends (#12864)
* [channels,cliprdr] refactor server channel (#12810)
* [channels,cliprdr] reset stream after use (#12855)
* [channels,drdynvc] add new PubSub events (#12760)
* [channels,rail] fix client handshake response (#12780)
* [channels,rdpdr] various enhancements (#12800, #12797, #12803)
* [channels,rdpgfx] fix server frame command returning success on write failure (#12828)
* [channels,rdpsnd] reject client audio formats with zero nChannels/nBlockAlign (server-side DoS) (#12829)
* [channels,rdpsnd] skip unusable playback backend during selection (#12830)
* Refactor printer queue (#12817)
* [ci,freebsd] update ci (#12823, #12824, #12825)
* [cmake,simd] guard CMAKE_OSX_ARCHITECTURES (#12802)
* [cmake] replace find_package(GLOBAL) (#12837)
* [cmake] fix use of pkg_check_module (#12838)
* [winpr,input] complete japanese keyboard mapping (#12836)
* winpr/input: Fix numpad mapping for japanese keyboards (#12845)
* [core,gateway] validate auth blob length in rdg_process_extauth_sspi (#12856)
* Restore fullscreen when maximizing a toggled fullscreen window (#12849)
* Fix(wfreerdp): Refresh Windows frame after fullscreen restore (#12848)
* Fix copying multiple items of the same type between xfreerdp sessions (#12834)
* [core,event] add StateChanged event (#12858)
* [core,nego] bound cookie tag check to remaining length (#12862)
* codec stats (#12860)
* Various warning fixes (#12749, #12813, #12866, #12831)
* [core,client] add PubSub events (#12757)
* [core,client] use correct interface pointer (#12766)
* [client,rdpewa] filter UserNotify events (#12767)
* [client,windows] honor /from-stdin in wfreerdp (#12821)
* [client,x11] release normal keys before modifiers (#12868)
* fix(client/SDL): do not treat an unrecognized mouse button as fatal (#12847)
* Proxy client context (#12865)
* [core,update] filter out unused/unknown (#12870)
* Azure/Entra undocumented stuff and request compaction (#12872, #12871, #12770)
* Various bounds checks (#12873, #12857)
* Sspi separate ansi unicode (#12874)
* Ci update qa (#12875)
* [channels,gfx] extract remaining header length (#12876)
* [cache,glyph] bound offset read to buffer length (#12881)
* Expose the correlationId in settings (#12879)
* [winpr,wtypes] fix WINPR_C23_ENUM_TYPE (#12882)
* [server,proxy] pass ntlm hostname (#12877)

## New Contributors
* @ramnes made their first contribution in (#12782)
* @grioghar made their first contribution in (#12829)
* @scottgeigel2 made their first contribution in (#12821)
* @metsw24-max made their first contribution in (#12856)
* @zorjen122 made their first contribution in (#12849)

For a complete and detailed change log since the last release run:
git log 3.27.0...3.26.0

# 2026-05-06 Version 3.26.0

Mostly a bugfix and maintenance release with a few nice additions:
* On mac os the H264 decoder now supports VideoToolbox
* The android client got a big overhaul, more has been promised

## CVE fixes
* 3 High ranking CVE, no numbers assigned yet.
  Monitor https://github.com/FreeRDP/FreeRDP/security/advisories for updates

## What's Changed
* cmake: Findyuv: Use correct pkgconfig name (#12666)
* Remove deallocator attribute from rfx_message_free (#12681)
* [winpr,utils] improve winpr/ntlm.h (#12677)
* rdpecam-v4l: stop the capture thread when streaming is cleared (#12690)
* fix(winpr,ncrypt): support PIV retired key slots for smartcard logon (#12684)
* [core,instance] fix deprecation guards (#12691)
* [ci,alt-arch] enable internal MD4, MD5 and RC4 (#12692)
* Add VideoToolbox H.264 support for ffmpeg (#12694)
* [client,common] add /args-from:file:<name> syntax (#12697)
* [ci,freebsd] update freebsd builds (#12698, #12700, #12701, #12702)
* [client, android] UI modernization, SQLCipher and more (#12685, #12686, #12687, #12730,
  #12731, #12736, #12737, #12688)
* [cmake,deps] use alias target for sso-mib (#12706)
* [core,settings] add auto reconnect triggered flag (#12709)
* Force YUV420P when videotoolbox is used (#12711)
* Release cleanups (#12712)
* [gdi,gfx] fix bounds checks and proxy unit tests (#12713)
* Improved input checks (#12714)
* [winpr,utils] add unit tests for command line parser (#12716)
* Cmdline fixes (#12717)
* [codec,planar] fix bounds checks (#12718)
* [client,common] add freerdp_client_settings_parse_command_line_argume… (#12724)
* [winpr,sspi] clean up ntlm code (#12732)

## New Contributors
* @fstanis made their first contribution in (#12694)

For a complete and detailed change log since the last release run:
git log 3.26.0...3.25.0

# 2026-04-23 Version 3.25.0

Bugfix and feature release.
* Experimental AV1 support has been added. This currently works only with FreeRDP based servers.
* Most notably there is now support for [MS-RDPEWA] (FIDO2 redirection)
* Android client received a (small) facelift
* Improved SDL3 client drawing performance
* Console output support for SDL3 (windows) and windows native client
* RDP proxy now supports NSCodec and RFX modes.
* RDP PRoxy now has smartcard emulation and SAM file support (via config file)
* Smartcard KSP support for NLA authentication

## CVE fixes
* CVE-2026-40254

## What's Changed
* [winpr,wlog] add WLog_SetGlobalPrefix (#12497)
* [channels,video] fix wrong cast (#12511)
* [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510)
* [client,sdl] create a copy of rdpPointer (#12512)
* [codec,video] properly pass intermediate format (#12518)
* [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520)
* winpr: improve libunwind backtraces (#12530)
* [server,shadow] remember selected caps (#12528)
* Zero credential data before free in NLA and NTLM context (#12532)
* [server,proxy] ignore missing client in input channel (#12536)
* [server,proxy] ignore rdpdr messages (#12537)
* [winpr,sspi] improve kerberos logging (#12538)
* Codec fixes (#12542)
* [winpr,sspi] Fix context nullptr handling (#12543)
* Dev 3.24.3 dev0 (#12545)
* Fix memory leak in `gdi_create_bitmap()` on `gdi_CreateBitmap` failure (`libfreerdp/gdi/graphics.c`) (#12547)
* Fix memory leak in `vgids_read_do_fkt()` on `Stream_New` failure (`libfreerdp/emu/scard/smartcard_virtual_gids.c`) (#12548)
* Proxy config improve (#12549)
* Proxy config improve (#12550)
* [client,sdl] clamp cursor hotspot (#12553)
* RFC: Research/av1 codec extension (#12527)
* [winpr,kerberos] fix krb_log_context_encryption (#12555)
* [client,sdl] fix global init return check (#12558)
* Fix remote credential with windows11h2 (#12560)
* Proxy scard auth improvements (#12561)
* [winpr,sspi] guard krb5_get_etype_info (#12562)
* [utils,smartcard] fix STATUS_BUFFER_TOO_SMALL (#12564)
* [client,common] do not manipulate security settings for smartcard-logon (#12567)
* [channels,audin] fix regression for microphone (#12570)
* [client,sdl] add SDL_KMOD_MODE and SDL_KMOD_LEVEL5 (#12569)
* Fix unbound strlen on slotDescription (#12571)
* build: Update FindFFmpeg.cmake to support Apple frameworks with 'lib' prefix (#12565)
* [channels,rdpewa] add WebAuthn virtual channel support (#12572)
* [core] fix freerdp_get_nla_sspi_error always returning 0 on client (#12574)
* [ci] enable rdpewa channel (#12576)
* small refactoring (#12578)
* Rdpewa unify notifications (#12581)
* [client,sdl] fix crash when clicking 'cancel' on PIN popup (#12580)
* [channels,drive] refine bounds checks (#12584)
* fix: smartcard logon with ECC keys and minidriver-assigned container names (#12585)
* Various papercuts (#12583)
* fix: console output on Windows client (#12573)
* [winpr,crt] dump stack on aligned memory errors (#12588)
* [client,x11] keep scancode input for Ctrl/Alt/Super combinations in /kbd:unicode mode (#12590)
* [codec,progressive] fix underflow guard in progressive_rfx_quant_sub (#12592)
* fix: wfreerdp floatbar visibility (#12594)
* [winpr,json] return a copy from WINPR_JSON_Print* (#12595)
* [client,sdl] drop WITH_DEBUG_SDL_EVENTS (#12599)
* Ncrypt and asn1 cleanup (#12604)
* Video channel fix (#12593)
* [codec,h264] fix media foundation backend (#12606)
* fix(sdl): detect Hyprland and river in tryFallback() (#12608)
* Proxy stress fixes (#12597)
* Add new fuzzer tests (#12613)
* fix(sdl): use SDL_Renderer instead of software surfaces (#12607)
* fix(sdl): BFS neighbor walk pop/begin mismatch in addOrUpdateDisplay (#12614)
* fix(sdl): promote first monitor as primary when subset excludes primary (#12618)
* [ci,android] default to only aarch64 (#12622)
* Fix process exit code on non-pidfd platforms (macOS, BSD)#12534) (#12586)
* warning cleanups (#12626)
* fix: prevent PostQuitMessage in RemoteApp WM_DESTROY handler (#12629)
* [winpr,ntlm] fix message cleanup across the SSPI lifecycle (#12609)
* Code bug fixes (#12632)
* Oss fixes (#12633)
* [client,android] add an option to enable keeping screen on when connected (#12630)
* [client, android] Fix layout overlaps, migrate to AndroidX, and update UI components (#12628)
* Proxy config tests (#12636)
* Proxy config optional targethost (#12637)
* [client,sdl] set SDL_HINT_SCREENSAVER_INHIBIT_ACTIVITY_NAME (#12639)
* Nightly deb fix (#12640, #12641, #12649, #12650, #12642, #12643)
* [winpr,input] fix korean keyboard mapping (#12646)
* [client,sdl] set hints before SDL_Init (#12644)
* Sdl inhibit option (#12647)
* [client,X11] fix residual race in xf_clipboard_formats_free (#12648)
* (sdl3): Fix oversized window on HiDPI Wayland (#12635)
* [cache,bitmap] fix off-by-one in bitmap_cache_put bounds check (#12651)
* [winpr,sspi] free fields buffer immediately (#12654)
* [codec,dsp] fix fencepost error in dsp_ima_clamp_step (#12655)

## New Contributors
* @Kotivskyi made their first contribution in (#12532)
* @Skinner927 made their first contribution in (#12571)
* @bluca made their first contribution in (#12572)
* @sitiom made their first contribution in (#12573)
* @mtixt made their first contribution in (#12590)
* @MrVampy made their first contribution in (#12608)
* @ZackaryShen made their first contribution in (#12629)
* @parasol-aser made their first contribution in (#12609)
* @svncibrahim made their first contribution in (#12628)

**Full Changelog**: https://github.com/FreeRDP/FreeRDP/compare/3.24.1...3.25.0

# 2026-03-25 Version 3.24.2

Bug and security fix release

## CVE fixes

We got 4 High and 2 Moderate security reports from
* Calvin Young - eWalker Consulting
* Enoch Chow - Isomorph Cyber

and 2 Modreate reports from
* [Sebastian Alba Vives] ***@***.***) Sebastián Alba

and 1 Moderate report from
* @prahal

CVE have been requested but not assigned yet. They will be published once assigned at
https://github.com/FreeRDP/FreeRDP/security

## What's Changed
* [channels,video] fix wrong cast (#12511)
* [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510)
* [client,sdl] create a copy of rdpPointer (#12512)
* [codec,video] properly pass intermediate format (#12518)
* [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520)
* winpr: improve libunwind backtraces (#12530)
* [server,shadow] remember selected caps (#12528)
* Zero credential data before free in NLA and NTLM context (#12532)
* [server,proxy] ignore missing client in input channel (#12536)
* [server,proxy] ignore rdpdr messages (#12537)
* [winpr,sspi] improve kerberos logging (#12538)
