CVE-2025-2586
A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1499.001OS Exhaustion Floodimpact85 % - Impacto secundario
T1499.004Application or System Exploitationimpact75 %
API abierta sin autenticación (AV:N/PR:N) permite flooding que agota recursos. CWE-400 y degradación de servicio indican DoS por consumo de recursos y disco.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-400
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2586",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2586",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-31T11:57:51.203673Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "88f9dc91856593d878b60ad9a67ffee8d4621ba5",
"versionType": "git"
}
],
"packageName": "lightspeed-service",
"collectionURL": "https://github.com/openshift/lightspeed-service",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_lightspeed"
],
"vendor": "Red Hat",
"product": "OpenShift Lightspeed",
"packageName": "openshift-lightspeed-tech-preview/lightspeed-service-api-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-03-31T12:15:15.073",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2025-2586",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2353998",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/openshift/lightspeed-service/pull/2369",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead to monitoring system degradation, increased disk usage, and potential service unavailability. Since the issue does not require authentication, an external attacker can exhaust CPU, RAM, and disk space, impacting both application and cluster stability."
},
{
"lang": "es",
"value": "Se detectó una falla en el servicio OpenShift Lightspeed, vulnerable a la inundación de solicitudes de API no autenticadas. Las consultas repetidas a endpoints inexistentes inflan el almacenamiento y el procesamiento de métricas, consumiendo recursos excesivos. Este problema puede provocar la degradación del sistema de monitorización, un mayor uso del disco y la posible indisponibilidad del servicio. Dado que el problema no requiere autenticación, un atacante externo puede agotar la CPU, la RAM y el espacio en disco, lo que afecta la estabilidad tanto de la aplicación como del clúster."
}
],
"lastModified": "2026-06-25T23:17:00.883",
"sourceIdentifier": "secalert@redhat.com"
}