CVE-2026-12353
Received Received - Intake

Out of Memory Condition in Red Hat Ceph Storage

Vulnerability report for CVE-2026-12353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Red Hat, Inc.

Description

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat rhcs *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated attacker to crash the Red Hat Certificate System (RHCS) Java process by sending repeated HTTP requests to the TLS endpoint. This triggers an Out of Memory condition, causing a denial of service (DoS). The system may require manual restart to recover depending on its configuration.

Detection Guidance

Monitor for repeated HTTP requests to the TLS endpoint of RHCS causing high memory usage. Check system logs for Out of Memory errors or Java process crashes. Use tools like netstat or ss to track persistent connections to the RHCS TLS port.

Impact Analysis

The vulnerability can lead to service disruption as the RHCS server crashes and becomes unavailable. This may cause downtime for certificate management services, affecting authentication and secure communications relying on RHCS.

Mitigation Strategies

Restrict access to the RHCS TLS endpoint via firewall rules. Limit the number of concurrent connections. Monitor memory usage and restart the Java process if it crashes. Apply patches once available from Red Hat.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12353. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart