CVE-2026-73198High· 7.5▾ TwilightA flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leadin…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the /ipa/i18n_messages endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0freeipa < 4.13.3Upgrade past the affected range:
freeipa 4.13.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73197High· 7.5A flaw was found in FreeIPA
CVE-2026-11861Critical· 9.6A flaw was found in FreeIPA
CVE-2026-19550High· 8.2A flaw was found in FreeIPA
CVE-2026-13097High· 8.7A privilege escalation flaw was found in FreeIPA
CVE-2025-61726High· 7.5The net/url package does not set a limit on the number of query parameters in a query
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak