A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-73197 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2474697 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2026-08-20 11:16
Updated : 2026-08-25 15:16
NVD link : CVE-2026-73197
Mitre link : CVE-2026-73197
CVE.ORG link : CVE-2026-73197
JSON object : View
Products Affected
redhat
- enterprise_linux
freeipa
- freeipa
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
