CVE-2026-10533

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en OpenShift Container Platform. Los pods completados con restartPolicy: Never no cuentan para los límites de pods de ResourceQuota, y los eventos de Kubernetes no están sujetos a cuota. Un usuario no privilegiado que puede crear pods en un namespace puede explotar esto para generar un gran volumen de eventos que se acumulan en etcd, causando degradación del rendimiento del servidor API en todo el clúster.

08 Jun 2026, 14:09

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-10533 - () https://access.redhat.com/security/cve/CVE-2026-10533 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2483727 - () https://bugzilla.redhat.com/show_bug.cgi?id=2483727 - Permissions Required
First Time Redhat
Redhat openshift Container Platform
CPE cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

01 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 15:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-10533

Mitre link : CVE-2026-10533

CVE.ORG link : CVE-2026-10533


JSON object : View

Products Affected

redhat

  • openshift_container_platform
CWE
CWE-770

Allocation of Resources Without Limits or Throttling