CVE-2026-73196

Discovered by AISLEPUBLISHEDCWE-770

Description

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.

CVSS Base Scores

CVSS v3.1(Primary)
4.3

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 10——
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat Enterprise Linux 9——

Credits

  • This issue was discovered by Found by AISLE in partnership with Red Hat.

References