Sploitus

CVE-2026-73196

No indexed exploits for CVE-2026-73196 yet

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.

Affected products
Freeipa
Redhat Enterprise Linux
= 6.0, 7.0, 8.0, 9.0, 10.0
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-770
NVD status
Analyzed
Published
2026-08-20

Workaround

To mitigate this issue, enforce conservative HTTP request-body limits on the `/ipa/session/json` endpoint to reject oversized payloads before they reach the vulnerable IPA parameter conversion. Additionally, if operationally feasible, restrict self-managed token creation to trusted users and implement monitoring or rate-limiting for repeated large authenticated requests. Changes to HTTP server configurations or FreeIPA permissions may require service restarts or reloads to take effect.

CVE-2026-73196 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-73196 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-73196 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.