UNKNOWN OpenStack
CVE-2026-71193
OSSA-2026-034: Cross-tenant DNS zone overlap and mDNS DoS via pool scheduling
Tore Anderson of Redpill Linpro AS reported that OpenStack Designate does not enforce cross-pool zone ownership checks when scheduling a zone to a non-default pool via the attribute filter. A tenant can create a sub-zone, super-zone, or duplicate of another tenant’s zone by targeting a different pool, enabling DNS hijack or denial of service. Independently, Omer Schwartz of Red Hat identified that the mDNS handler performs pool-blind record lookups, causing a deterministic denial of service when
Affected Products
- Designate: >=1.0.0 <20.0.2, ==21.0.0, ==22.0.0
- CVE-2026-71193
- CVE-2026-71194
References
- https://security.openstack.org/ossa/OSSA-2026-034.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-71193
- https://nvd.nist.gov/vuln/detail/CVE-2026-71194
This unknown severity vulnerability was published on 2026-08-11 via OpenStack. Affected: Designate: >=1.0.0 <20.0.2, ==21.0.0, ==22.0.0, CVE-2026-71193, CVE-2026-71194.
vulnfeed aggregates 11443 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.