mDNS Handler Vulnerability in OpenStack Designate
CVE-2026-71194

6.8MEDIUM

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-71194?

The mDNS handler in OpenStack Designate prior to version 22.0.2 is susceptible to an input validation vulnerability that can lead to failures in DNS record resolutions. This issue arises when two zones with the same name exist in different pools, causing a deterministic error that results in the handler rejecting all DNS queries along that resolution path. This vulnerability can be exploited by sending a single unauthenticated UDP packet, and it affects both cross-tenant and same-tenant zone configurations. Notably, existing BIND9 view configurations do not provide any mitigation for this issue, highlighting the need for urgent attention and remediation.

Affected Version(s)

Designate 1.0.0 < 20.0.2

Designate 21.0.0 < 21.0.1

Designate 22.0.0 < 22.0.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.