Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read
Published Aug 20, 2026
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
|
Configuration 1
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
ipa
Affected
Red Hat Enterprise Linux 6
ipa
Out of support scope
Red Hat Enterprise Linux 7
ipa
Affected
Red Hat Enterprise Linux 8
ipa
Affected
Red Hat Enterprise Linux 9
ipa
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 6 | ipa | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 8 | ipa | Affected | n/a |
| Red Hat Enterprise Linux 9 | ipa | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, configure Apache to enforce a request-body limit for the `/ipa/i18n_messages` endpoint. This can be achieved by adding `LimitRequestBody` directive within the Apache configuration for IPA. For example, to limit the request body to 1MB, add `LimitRequestBody 1048576` to the relevant `<Location "/ipa/i18n_messages">` block or a broader `/ipa/*` location. A restart of the Apache HTTP Server (`httpd`) service is required for the changes to take effect, which may temporarily impact FreeIPA service availability. If a reverse proxy or load balancer is used, ensure it also enforces an equivalent body-size limit.
Red Hat mitigation
To mitigate this issue, configure Apache to enforce a request-body limit for the `/ipa/i18n_messages` endpoint. This can be achieved by adding `LimitRequestBody` directive within the Apache configuration for IPA. For example, to limit the request body to 1MB, add `LimitRequestBody 1048576` to the relevant `<Location "/ipa/i18n_messages">` block or a broader `/ipa/*` location. A restart of the Apache HTTP Server (`httpd`) service is required for the changes to take effect, which may temporarily impact FreeIPA service availability. If a reverse proxy or load balancer is used, ensure it also enforces an equivalent body-size limit.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Aug 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00429) | 34.78th | v5 (v2026.06.15) |
| Aug 21, 2026 | 0.35% (0.00347) | 28.01th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/errata/RHSA-2026:70564 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72279 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-73198 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2472960 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73198
- https://www.cve.org/CVERecord?id=CVE-2026-73198
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:70564 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:72279 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-73198 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2472960 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73198 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73198 |
Change history (0)
No recorded changes yet.