Out of Memory Vulnerability in Red Hat Cloud Storage (RHCS)
CVE-2026-12353

5.3MEDIUM

What is CVE-2026-12353?

An unauthenticated attacker could exploit a vulnerability in Red Hat Cloud Storage (RHCS) by sending a series of HTTP requests to the TLS endpoint, effectively triggering an Out of Memory condition that causes the Java process to crash. Depending on the server's configuration, this may necessitate manual intervention to restore service availability.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Thibault Guittet (Red Hat).
.