CVE Feed

    Dashboard / CVE / CVE-2025-2586

    CVE-2025-2586

    A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability.

    Published:Mar 31, 2025
    Last Modified:Jun 25, 2026
    EPS:Mar 31, 2025
    EPSS Score:0.00387
    CVSS Score:7.5

    Affected Products

    Vendor
    Redhat
    Product
    Openshift Lightspeed

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High