← All Advisories

CVE-2026-73197

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-73197

Key Details

CVECVE-2026-73197
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-28
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
freeipafreeipa
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service. (NVD)

What to Do

Monitor Red Hat's and freeipa's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73197
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73197
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-73197