# CVE-2026-12353

## Summary

- **CVE ID:** CVE-2026-12353
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-772
- **Published:** Jul 23, 2026
- **Last Modified:** Jul 24, 2026

## Description

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

## Affected Products

No affected products listed.

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-12353)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2489056)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 36.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._