CVE-2026-12353
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-772: Missing Release of Resource after Effective Lifetime
References
- https://access.redhat.com/security/cve/CVE-2026-12353
- https://bugzilla.redhat.com/show_bug.cgi?id=2489056
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.