CVE-2026-73198

EUVD-2026-63244
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.88%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
freeipafreeipa
𝑥
< 4.13.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeipa
bookworm
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeipa
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ipa-client
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-epn
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-client-samba
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-luna
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-selinux-nfast
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-common
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-encrypted-dns
RHEL 9
0:4.13.4-1.el9_8
fixed
ipa-server-trust-ad
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaclient
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipalib
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipaserver
RHEL 9
0:4.13.4-1.el9_8
fixed
python3-ipatests
RHEL 9
0:4.13.4-1.el9_8
fixed