Bug 2520171 - CVE-2026-73197 freeipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read [fedora-all]
Summary: CVE-2026-73197 freeipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migra...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: IPA Maintainers
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["65457596-cb10-4e2d-b669-8...
Depends On:
Blocks: CVE-2026-73197
TreeView+ depends on / blocked
 
Reported: 2026-08-20 10:08 UTC by Vladimir Vasilev
Modified: 2026-09-04 01:26 UTC (History)
7 users (show)

Fixed In Version: freeipa-4.13.3-1.1.fc44 freeipa-4.13.3-1.1.fc43
Clone Of:
Environment:
Last Closed: 2026-08-25 01:02:49 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-08-20 10:08:05 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

AI_ONLY_REPORT
package: ipa-4.13.1-3.el10
------
Summary: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded  
Request Body Read: oversized unauthenticated form POST requests can force  
the migration handler to read attacker-controlled request bodies fully into  
memory, causing worker memory pressure and service degradation.
Requirements to exploit: Network access to `/ipa/migration/migration.py`  
and the ability to send large POST requests with  
`application/x-www-form-urlencoded`; no authentication is required.  
Deployments that already enforce strict front-end request-body limits or do  
not expose this endpoint materially reduce exploitability.
Component affected: `ipa-4.13.1-3.el10`, `install/migration/migration.py`,  
Apache `/ipa/migration` WSGI endpoint, `application()`
Version affected: `ipa-4.13.1-3.el10`
Patch available: no released package fix established; proposed patch  
included below
Version fixed: unknown
Upstream coordination: Not notified.
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L - 5.3 (MEDIUM)
AV:N - The issue is reachable over HTTP(S) through the exposed migration  
endpoint.
AC:L - Exploitation requires only sending an oversized POST body; no  
race or special precondition was established.
PR:N - The endpoint is configured to allow unauthenticated access.
UI:N - No user interaction is required.
S:U - The impact is limited to the vulnerable service's own security  
scope.
C:N - No confidentiality impact was established.
I:N - No integrity impact was established.
A:L - The demonstrated effect is memory pressure and service degradation  
in affected workers, rather than full system compromise.
Impact: Important. Red Hat guidance classifies flaws that allow remote  
users to cause a denial of service as Important. This issue is a remote,  
unauthenticated availability flaw against a web-facing endpoint in the  
shipped configuration. It is not Critical because no code execution or  
confidentiality/integrity impact was established, and deployment-specific  
body-size limits can reduce exploitability.
Embargo: no
Reason: This is an availability-only issue with straightforward  
mitigations, including disabling the migration endpoint where unused or  
enforcing conservative request-body limits at the HTTP front end.
Acknowledgement: Aisle Research
Vulnerability Details: The password migration WSGI handler accepts  
form-encoded POST requests, trusts `CONTENT_LENGTH`, and reads that many  
bytes from `wsgi.input` into memory before validating the request contents.  
There is no application-level upper bound before the read:
```python
install/migration/migration.py
try:
     length = int(environ.get("CONTENT_LENGTH"))
except (ValueError, TypeError):
     return bad_request(start_response)


query_string = environ["wsgi.input"].read(length).decode("utf-8")
```
The shipped Apache template exposes the migration directory without  
authentication:
```apache
install/share/ipa.conf.template
Alias /ipa/migration "/usr/share/ipa/migration"
<Directory "/usr/share/ipa/migration">
     AllowOverride None
     Satisfy Any
     Require all granted
     Options ExecCGI
     AddHandler wsgi-script .py
</Directory>
```


In deployments using this endpoint, an unauthenticated client can submit  
oversized request bodies and force a WSGI worker to allocate  
attacker-controlled data in memory. This can increase RSS, slow request  
handling, and in some deployments lead to worker recycling or service  
disruption. No direct confidentiality or integrity impact was established  
from the available evidence. No request-body cap was identified in the  
shipped template configuration, although external reverse proxies or HTTP  
server hardening may reduce or block exploitability.
Steps to reproduce:
1. Deploy `ipa-4.13.1-3.el10` with the shipped Apache configuration that  
exposes `/ipa/migration/migration.py`.
2. Confirm the endpoint is reachable without authentication:
```bash
curl -k -i https://<host>/ipa/migration/migration.py -X POST  
-H 'Content-Type: application/x-www-form-urlencoded'  
--data 'username=a&password=b'
```
3. Send an oversized unauthenticated POST body:
```bash
python3 - <<'PY'
import requests
u='https://<host>/ipa/migration/migration.py'
d='username=a&password='+'A'*(200*1024*1024)
print(requests.post(u,data=d,headers={'Content-Type':'application/x-www-form-urlencoded'},verify=False,timeout=120).status_code)
PY
```
4. Repeat from multiple clients or in a loop.
5. Observe `httpd`/WSGI worker RSS growth and service degradation,  
including higher memory pressure, slower responses, or worker  
recycling/failure.
Mitigation: If the migration endpoint is not needed, disable or unpublish  
`/ipa/migration`. Otherwise, enforce a conservative request-body limit for  
this path at the HTTP front end so oversized POST bodies are rejected  
before they reach the WSGI script.
Proposed Fix: Reject negative or excessively large request bodies before  
reading from `wsgi.input`.
```diff
diff --git a/install/migration/migration.py b/install/migration/migration.py
index 0000000..0000000 100644
— a/install/migration/migration.py
+++ b/install/migration/migration.py
@@ -31,6 +31,8 @@ from ipapython import ipaldap
from ipalib import errors, create_api
logger = logging.getLogger(os.path.basename(_file_))
+MAX_REQUEST_BODY = 1024 * 1024  # 1 MiB, sufficient for username/password  
form
+
@@ -83,6 +85,10 @@ def application(environ, start_response):
try:
length = int(environ.get("CONTENT_LENGTH"))
except (ValueError, TypeError):
+        return bad_request(start_response)
+
+    if length < 0 or length > MAX_REQUEST_BODY:
return bad_request(start_response)
query_string = environ["wsgi.input"].read(length).decode("utf-8")
```
------
This report was generated using AI technology. Always review AI-generated  
content prior to use

Comment 1 Fedora Update System 2026-08-20 11:21:28 UTC
FEDORA-2026-903d904933 (freeipa-4.13.3-1.fc44 and samba-4.24.6-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-903d904933

Comment 2 Fedora Update System 2026-08-21 05:41:09 UTC
FEDORA-2026-903d904933 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-903d904933`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-903d904933

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 3 Fedora Update System 2026-08-21 09:48:54 UTC
FEDORA-2026-3a48220f1f (freeipa-4.13.3-1.1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a48220f1f

Comment 4 Fedora Update System 2026-08-22 01:39:40 UTC
FEDORA-2026-903d904933 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-903d904933`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-903d904933

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-08-22 02:21:15 UTC
FEDORA-2026-3a48220f1f has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-3a48220f1f`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3a48220f1f

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-08-25 01:02:49 UTC
FEDORA-2026-903d904933 (freeipa-4.13.3-1.1.fc44 and samba-4.24.6-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2026-09-04 01:26:35 UTC
FEDORA-2026-3a48220f1f (freeipa-4.13.3-1.1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.