CVE-2026-73197
EUVD-2026-6324020.08.2026, 11:16
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
| freeipa | freeipa | 𝑥 < 4.13.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| ipa-client |
| ||
| ipa-client-common |
| ||
| ipa-client-encrypted-dns |
| ||
| ipa-client-epn |
| ||
| ipa-client-samba |
| ||
| ipa-common |
| ||
| ipa-selinux |
| ||
| ipa-selinux-luna |
| ||
| ipa-selinux-nfast |
| ||
| ipa-server |
| ||
| ipa-server-common |
| ||
| ipa-server-dns |
| ||
| ipa-server-encrypted-dns |
| ||
| ipa-server-trust-ad |
| ||
| python3-ipaclient |
| ||
| python3-ipalib |
| ||
| python3-ipaserver |
| ||
| python3-ipatests |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| ipa-client |
| ||
| ipa-client-common |
| ||
| ipa-common |
| ||
| ipa-debuginfo |
| ||
| ipa-python-compat |
| ||
| ipa-server |
| ||
| ipa-server-common |
| ||
| ipa-server-dns |
| ||
| ipa-server-trust-ad |
| ||
| python2-ipaclient |
| ||
| python2-ipalib |
| ||
| python2-ipaserver |
|