What is CVE-2026-12353?
This vulnerability allows an unauthenticated attacker to trigger an Out of Memory condition in the Java process by repeatedly sending HTTP requests to the TLS endpoint, crashing the RHCS server. Depending on the configuration, manual intervention to restart the server may be necessary.
Azərbaycanca: Bu zəiflik autentifikasiya olunmamış hücumçunun TLS endpoint-ə təkrar HTTP sorğuları göndərərək Java prosesində Out of Memory vəziyyətini tetiklemesine və RHCS serverini çökdürmesine imkan verir. Server konfiqurasiyasından asılı olaraq əl ilə yenidən başlatma tələb oluna bilər.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Does an attacker exploiting CVE-2026-12353 need to be authenticated?
No, this vulnerability allows an unauthenticated attacker to exploit it by repeatedly sending HTTP requests to the TLS endpoint.
What is the impact on the server when CVE-2026-12353 is successfully exploited?
The vulnerability triggers an Out of Memory condition in the Java process, crashing the RHCS server. Depending on the configuration, manual intervention to restart the server may be necessary.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.