Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, enforce conservative HTTP request-body limits on the `/ipa/session/json` endpoint to reject oversized payloads before they reach the vulnerable IPA parameter conversion. Additionally, if operationally feasible, restrict self-managed token creation to trusted users and implement monitoring or rate-limiting for repeated large authenticated requests. Changes to HTTP server configurations or FreeIPA permissions may require service restarts or reloads to take effect.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service. | |
| Title | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-20T10:31:58.189Z
Reserved: 2026-08-11T12:49:53.470Z
Link: CVE-2026-73196
No data.
Status : Awaiting Analysis
Published: 2026-08-20T11:16:21.417
Modified: 2026-08-20T13:08:53.900
Link: CVE-2026-73196
No data.
OpenCVE Enrichment
No data.