CVE-2026-73196

MEDIUM CVSS 3.1: 6.5 EPSS 0.22%
Updated Aug 24, 2026
Freeipa
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 4.13.3
Fixed In 4.13.3
Type CWE-770 (Allocation Without Limits)
Vendor Freeipa
Public PoC No

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources.

This can lead to a denial of service, degrading the availability of the IPA service.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 6

Configuration From (including) Up to (excluding)
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Freeipa Freeipa
cpe:2.3:a:freeipa:freeipa:*:*:*:*:*:*:*:*
4.13.3