Red HatCVE-2026-12353
Red Hat Certificate System 9: resource leak
Medium5.3CVE-2026-12353 · Published Jul 23, 2026 · updated Jul 24, 2026
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Certificate System 9 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-772
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Red Hat gdk-pixbuf.: out-of-bounds read | Medium5.3 | No fix yet |
| Jul 23 | Red Hat odh-dashboard: authentication bypass | High8.8 | No fix yet |
| Jul 23 | Red Hat libcupsfilters: infinite loop | High7.5 | No fix yet |
| Jul 23 | Red Hat GNU nano: information disclosure | Medium6.8 | No fix yet |
| Jul 22 | Red Hat librest: attacker could bypass PKCE protections | Medium6.8 | No fix yet |
| Jul 22 | Red Hat Directory Server 11: denial of service | Medium5.3 | No fix yet |