Executive brief
Red Hat Certificate System (RHCS) is a software framework used to manage digital certificates and secure communications. A vulnerability has been identified where an unauthenticated attacker can crash the system by sending a large volume of specific web requests. This results in a denial of service, potentially requiring manual intervention from administrators to restart the service and restore security operations.
Technical details
The vulnerability is classified as a resource leak (CWE-772) within the Java-based Red Hat Certificate System (RHCS). An unauthenticated remote attacker can exploit this by repeatedly sending HTTP requests to the TLS endpoint, which causes the application to fail to release memory resources. Over time, this leads to an Out of Memory (OOM) condition that crashes the Java process. The attack requires no special privileges or user interaction. Depending on the environment configuration, the service may not automatically recover, necessitating manual administrative intervention to restart the pki-core or dogtag-pki components.
Affected products
- Red Hat Red Hat Certificate System 9 9
- Red Hat Red Hat Enterprise Linux 10 dogtag-pki
- Red Hat Red Hat Enterprise Linux 9 pki-core
- Red Hat Red Hat Enterprise Linux 8 pki-core:10.6/pki-core
Timeline
- 2026-06-15: other: Reported to Red Hat Bugzilla
- 2026-07-23: advisory: NVD publication date