VYPR

apk package

chainguard/py3.13-ipaclient

pkg:apk/chainguard/py3.13-ipaclient

Vulnerabilities (6)

  • CVE-2026-73198HigAug 20, 2026
    affected < 4.13.3-r0fixed 4.13.3-r0

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsive

  • CVE-2026-73197HigAug 20, 2026
    affected < 4.13.3-r0fixed 4.13.3-r0

    A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory,

  • CVE-2026-73196MedAug 20, 2026
    affected < 4.13.3-r0fixed 4.13.3-r0

    A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources.

  • CVE-2026-11861CriAug 20, 2026
    affected < 4.13.3-r0fixed 4.13.3-r0

    A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name

  • CVE-2026-19550HigAug 11, 2026
    affected < 4.13.3-r0fixed 4.13.3-r0

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an at

  • CVE-2016-5404MedSep 7, 2016
    affected < 4.12.5-r0fixed 4.12.5-r0

    The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.