Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read
Published Aug 20, 2026
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
|
Configuration 1
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
ipa
Affected
Red Hat Enterprise Linux 6
ipa
Out of support scope
Red Hat Enterprise Linux 7
ipa
Affected
Red Hat Enterprise Linux 8
ipa
Affected
Red Hat Enterprise Linux 9
ipa
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 6 | ipa | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 9 | ipa | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
If the `/ipa/migration` endpoint is not required, it can be disabled by commenting out or removing the `Alias /ipa/migration` and its corresponding `<Directory>` block in the Apache configuration file (e.g., `/etc/httpd/conf.d/ipa.conf`).
Alternatively, to limit the size of request bodies processed by the `/ipa/migration` endpoint, add the `LimitRequestBody` directive within the `<Directory "/usr/share/ipa/migration">` block in your Apache configuration, setting a conservative limit such as 1 MiB (1048576 bytes):
```apache <Directory "/usr/share/ipa/migration"> LimitRequestBody 1048576 # ... other directives ... </Directory> ```
After modifying the Apache configuration, the `httpd` service must be reloaded or restarted for the changes to take effect. This may temporarily interrupt service.
Red Hat mitigation
If the `/ipa/migration` endpoint is not required, it can be disabled by commenting out or removing the `Alias /ipa/migration` and its corresponding `<Directory>` block in the Apache configuration file (e.g., `/etc/httpd/conf.d/ipa.conf`). Alternatively, to limit the size of request bodies processed by the `/ipa/migration` endpoint, add the `LimitRequestBody` directive within the `<Directory "/usr/share/ipa/migration">` block in your Apache configuration, setting a conservative limit such as 1 MiB (1048576 bytes): ```apache <Directory "/usr/share/ipa/migration"> LimitRequestBody 1048576 # ... other directives ... </Directory> ``` After modifying the Apache configuration, the `httpd` service must be reloaded or restarted for the changes to take effect. This may temporarily interrupt service.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Aug 25, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00429) | 34.78th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.35% (0.00347) | 28.01th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:70564 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72279 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-73197 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2474697 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73197
- https://www.cve.org/CVERecord?id=CVE-2026-73197
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:70564 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:72279 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-73197 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2474697 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73197 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73197 |
Change history (0)
No recorded changes yet.