CVE-2026-73197

Discovered by AISLEPUBLISHEDCWE-770

Description

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.

CVSS Base Scores

CVSS v3.1(Primary)
7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 100:4.13.4-1.el10_2unaffected
Red HatRed Hat Enterprise Linux 90:4.13.4-1.el9_8unaffected
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——

Credits

  • Red Hat would like to thank AISLE Research for reporting this issue.

References