High severity7.5NVD Advisory· Published Aug 20, 2026· Updated Aug 20, 2026
CVE-2026-73197
CVE-2026-73197
Description
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the /ipa/migration/migration.py endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.