CVE-2026-12353: Red Hat Certificate System 9

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

Affected products

Published 2026-07-23. Last modified 2026-07-24.