Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding
Published Aug 20, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.43%
Description
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
Configuration 1
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
ipa
Fix deferred
Red Hat Enterprise Linux 6
ipa
Out of support scope
Red Hat Enterprise Linux 7
ipa
Fix deferred
Red Hat Enterprise Linux 8
ipa
Fix deferred
Red Hat Enterprise Linux 9
ipa
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ipa | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | ipa | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ipa | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | ipa | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | ipa | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, enforce conservative HTTP request-body limits on the `/ipa/session/json` endpoint to reject oversized payloads before they reach the vulnerable IPA parameter conversion. Additionally, if operationally feasible, restrict self-managed token creation to trusted users and implement monitoring or rate-limiting for repeated large authenticated requests. Changes to HTTP server configurations or FreeIPA permissions may require service restarts or reloads to take effect.
Red Hat mitigation
To mitigate this issue, enforce conservative HTTP request-body limits on the `/ipa/session/json` endpoint to reject oversized payloads before they reach the vulnerable IPA parameter conversion. Additionally, if operationally feasible, restrict self-managed token creation to trusted users and implement monitoring or rate-limiting for repeated large authenticated requests. Changes to HTTP server configurations or FreeIPA permissions may require service restarts or reloads to take effect.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00426) | 34.56th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.22% (0.00221) | 12.90th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-73196 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2474712 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73196
- https://www.cve.org/CVERecord?id=CVE-2026-73196
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-73196 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2474712 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73196 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73196 |
Change history (0)
No recorded changes yet.