Description
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Timeline
| 2026-03-16: | Reported to Red Hat. |
| 2026-03-16: | Made public. |
Credits
Red Hat would like to thank Chris Sinclair for reporting this issue.
References
access.redhat.com/security/cve/CVE-2026-10533
bugzilla.redhat.com/show_bug.cgi?id=2483727 (RHBZ#2483727)