CVE-2026-12353
Awaiting Analysis Awaiting Analysis - Queue

Out of Memory Condition in Red Hat Ceph Storage

Vulnerability report for CVE-2026-12353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-24

Assigner: Red Hat, Inc.

Description

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-24
Generated
2026-08-13
AI Q&A
2026-07-23
EPSS Evaluated
2026-08-11
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat red_hat_certificate_system *
redhat rhcs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker to crash the Red Hat Certificate System (RHCS) Java process by sending repeated HTTP requests to the TLS endpoint. This triggers an Out of Memory condition, causing a denial of service (DoS). The system may require manual restart to recover depending on its configuration.

Detection Guidance

Monitor for repeated HTTP requests to the TLS endpoint of RHCS causing high memory usage. Check system logs for Out of Memory errors or Java process crashes. Use tools like netstat or ss to track persistent connections to the RHCS TLS port.

Impact Analysis

The vulnerability can lead to service disruption as the RHCS server crashes and becomes unavailable. This may cause downtime for certificate management services, affecting authentication and secure communications relying on RHCS.

Compliance Impact

This vulnerability could lead to a denial of service (DoS) condition by crashing the Java process, potentially disrupting services handling sensitive data. For GDPR, this may impact availability of personal data processing systems, requiring incident reporting under Article 33. For HIPAA, it could affect the availability of systems storing protected health information, potentially violating the Security Rule's integrity and availability requirements.

Mitigation Strategies

Restrict access to the RHCS TLS endpoint via firewall rules. Limit the number of concurrent connections. Monitor memory usage and restart the Java process if it crashes. Apply patches once available from Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12353. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart