Back to overview

CVE-2026-12353

MEDIUM
5.3
CVSS 3.1
Description
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

Metadata

CVE ID
CVE-2026-12353
State
PUBLISHED
Assigner
redhat
Reserved
2026-06-15 21:27 UTC
Published
2026-07-23 19:10 UTC
Last updated
2026-07-23 19:16 UTC
Primary CWE
CWE-772
Missing Release of Resource after Effective Lifetime
Vendor / Product
Red Hat / Red Hat Certificate System 9
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products (4)
VendorProductPlatformVersions
Red Hat Red Hat Certificate System 9
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 8
Red Hat Red Hat Enterprise Linux 9
Weakness (CWE)
CWESourceDescription
CWE-772 cna Missing Release of Resource after Effective Lifetime
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Back to overview