CVE-2026-12353
Public on 2026-07-23
Modified on 2026-07-24
Description
An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | jss | Not Affected | ||
| Amazon Linux 2 - Core | ldapjdk | Not Affected | ||
| Amazon Linux 2 - Core | resteasy-base | Not Affected | ||
| Amazon Linux 2 - Core | tomcatjss | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |