Red Hat Certificate System
Red Hat Certificate System is a security framework that manages user identities and helps keep communications private. It protects internet traffic against hackers and bots by simplifying how a business deploys and adopts public-key cryptography, which is responsible for data encryption, decryption, authentication, and more.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-78323 | Synopsis A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections. | Date |
| Severity Important | Advisory/CVECVE-2026-68494 | Synopsis A flaw was found in jackson-core. A remote attacker can exploit an incomplete fix in the non-blocking JSON parser by streaming specially crafted JSON data in small chunks. This bypasses the intended number length constraint, causing the parser to accumulate excessive memory per connection. This uncontrolled memory growth can lead to a denial of service (DoS) by exhausting the Java Virtual Machine (JVM) heap. | Date |
| Severity Moderate | Advisory/CVECVE-2026-18401 | Synopsis A flaw was found in jackson-core. The non-blocking (asynchronous) JSON parser does not properly enforce the maximum number length constraint. A remote attacker can exploit this by submitting a specially crafted JSON document containing an arbitrarily long number to an application using the asynchronous parser. This can lead to excessive memory allocation and CPU exhaustion, resulting in a denial of service (DoS) for the affected application. | Date |
| Severity Moderate | Advisory/CVECVE-2026-18369 | Synopsis A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:48095) Important: RHCS 10.8 bug fix and enhancement update | Synopsis Important: RHCS 10.8 bug fix and enhancement update | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.