Medium severity4.3NVD Advisory· Published Aug 20, 2026· Updated Aug 24, 2026
CVE-2026-73196
CVE-2026-73196
Description
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords8 versionspkg:apk/chainguard/freeipapkg:apk/chainguard/freeipa-docpkg:apk/chainguard/py3.13-ipaclientpkg:apk/chainguard/py3.13-ipalibpkg:apk/chainguard/py3.13-ipaplatformpkg:apk/chainguard/py3.13-ipapythonpkg:apk/chainguard/py3.13-ipaserverpkg:apk/chainguard/py3.13-ipatests
< 4.13.3-r0+ 7 more
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
- (no CPE)range: < 4.13.3-r0
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-73196nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.