Skip to content
Red HatCVE-2026-73198

Red Hat FreeIPA. A remote: resource exhaustion

High7.5CVE-2026-73198 · Published Aug 20, 2026 · updated Sep 24, 2026

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat multicloud-operators-subscription: information disclosure
High7.7Aug 20
A flaw was found in the multicloud-operators-subscription component
Critical9.9Aug 20
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Low2.5Aug 20
Red Hat lighthouse: information disclosure
Medium5.4Aug 20
Red Hat Lighthouse. A remote attacker: privilege escalation
Low3.7Aug 20
A flaw was found in Kata Containers
High8.1Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.