CVE-2026-73197
⚠️ highSummary
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
CVSS Score
7.5
High
EPSS Score
0.3
Exploit Probability
Published Date
2026-08-20
First Seen: 2026-08-21
📊 Relative Risk Intelligence
This CVE is Moderate Risk - more severe than 67.9% of all 350,976 vulnerabilities in our database.
#112,560
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Aug 25, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Red Hat would like to thank AISLE Research for reporting this issue.
SSVC data provided by
CISA
Last Modified
2026-08-25
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)