CVE-2026-71194
EUVD-2026-5769212.08.2026, 23:17
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openstack | designate | 1.0.0 ≤ 𝑥 < 20.0.2 | CNA |
| openstack | designate | 21.0.0 ≤ 𝑥 < 21.0.1 | CNA |
| openstack | designate | 22.0.0 ≤ 𝑥 < 22.0.2 | CNA |
Debian Releases