CVE-2026-10533
published 2026-06-01CVE-2026-10533: A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events…
PriorityP428medium5CVSS 3.1
AVNACLPRLUINSCCNINAL
EPSS
0.23%
14.0th percentile
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openshift: openshift: non-admin user can bypass ResourceQuota and flood etcd with events causing cluster-wide API degradation
vendor_redhat·2026-03-16·CVSS 5.0
CVE-2026-10533 [MEDIUM] CWE-770 openshift: openshift: non-admin user can bypass ResourceQuota and flood etcd with events causing cluster-wide API degradation
openshift: openshift: non-admin user can bypass ResourceQuota and flood etcd with events causing cluster-wide API degradation
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events
GHSA
A flaw was found in OpenShift Container Platform.
ghsa_unreviewed·2026-06-01
CVE-2026-10533 [MEDIUM] CWE-770 A flaw was found in OpenShift Container Platform.
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
No detection rules found.
No public exploits indexed.
2026-06-01
Published