Out of Memory Vulnerability in Red Hat Cloud Storage (RHCS)
CVE-2026-12353
5.3MEDIUM
What is CVE-2026-12353?
An unauthenticated attacker could exploit a vulnerability in Red Hat Cloud Storage (RHCS) by sending a series of HTTP requests to the TLS endpoint, effectively triggering an Out of Memory condition that causes the Java process to crash. Depending on the server's configuration, this may necessitate manual intervention to restore service availability.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Thibault Guittet (Red Hat).