CVE-2025-2586

Source
https://cve.org/CVERecord?id=CVE-2025-2586
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2586.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-2586
Published
2025-03-31T11:33:24Z
Modified
2026-10-08T02:50:55Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Ols: unauthenticated metrics flooding in openshift lightspeed service leading to resource exhaustion
Details

A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2586.json"
}
References

Affected packages

Git / github.com/openshift/lightspeed-service

Affected ranges

Type
GIT
Repo
https://github.com/openshift/lightspeed-service
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2586.json"