PT-2026-71364 · Openstack · Openstack Designate

CVE-2026-71194

·

Published

2026-08-12

·

Updated

2026-08-13

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Designate versions prior to 22.0.2
Description The mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. If two zones with the same name exist across different pools, the lookup fails, leading the handler to return REFUSED for all DNS queries through that path. The handle notify() function is exploitable via a single unauthenticated UDP packet. This issue affects legitimate same-tenant cross-pool configurations and is not mitigated by BIND9 views, as mDNS operates as a shared service upstream of view configurations.
Recommendations Update to version 22.0.2 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71194

Affected Products

Openstack Designate