A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade freeipa-server | Sep 18, 2026 | Sep 11, 2026 |
| Redhat_linux | — | Upgrade ipa-client-debuginfoUpgrade ipa-server-dnsUpgrade ipa-debugsourceNo solution existsUpgrade ipa-client-commonUpgrade ipa-server-trust-adUpgrade ipa-server-commonUpgrade ipa-server-encrypted-dnsUpgrade ipa-selinux-nfastUpgrade ipa-server-debuginfoUpgrade python3-ipalibUpgrade ipa-debuginfoUpgrade python3-ipaclientUpgrade ipa-serverUpgrade ipa-commonUpgrade python3-ipaserverUpgrade ipa-selinuxUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-selinux-lunaUpgrade python3-ipatestsUpgrade ipa-client-epnUpgrade ipa-client-sambaUpgrade ipa-clientUpgrade ipa-client-encrypted-dns | Aug 24, 2026 | Aug 20, 2026 |
| Rocky_linux | — | Upgrade ipa-debuginfoUpgrade ipa-debugsourceUpgrade ipa-server-trust-adUpgrade ipa-server-encrypted-dnsUpgrade ipa-clientUpgrade ipa-serverUpgrade ipa-client-debuginfoUpgrade ipa-client-encrypted-dnsUpgrade ipa-server-debuginfoUpgrade ipa-server-trust-ad-debuginfoUpgrade ipa-client-epnUpgrade ipa-client-samba | Sep 28, 2026 | Sep 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub