CVE-2026-73197
—CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
Description
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
In the news0 stories
No ingested article mentions this CVE yet.