A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 01 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster. | |
| Title | Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation | |
| First Time appeared |
Redhat
Redhat openshift |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:openshift:4 | |
| Vendors & Products |
Redhat
Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-01T13:19:29.978Z
Reserved: 2026-06-01T11:32:36.795Z
Link: CVE-2026-10533
No data.
Status : Awaiting Analysis
Published: 2026-06-01T15:16:33.443
Modified: 2026-06-01T16:57:45.130
Link: CVE-2026-10533
No data.
OpenCVE Enrichment
Updated: 2026-06-01T17:00:13Z
Weaknesses