CVE-2026-71194
Received Received - Intake

OpenStack Designate mDNS Pool-Blind Lookup Failure Leads to DNS Query Refusal

Vulnerability report for CVE-2026-71194, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: MITRE

Description

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openstack designate to 22.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenStack Designate before 22.0.2 involves the mDNS handler performing pool-blind lookups for DNS queries. When two zones share the same name across different pools, the lookup fails deterministically, causing the handler to return REFUSED for all DNS queries through that path. The issue is exploitable via a single unauthenticated UDP packet through the _handle_notify path.

Impact Analysis

This vulnerability can disrupt DNS resolution for all queries routed through the affected mDNS handler, leading to service outages or degraded performance. It may also allow attackers to cause denial-of-service conditions by sending a single unauthenticated packet.

Mitigation Strategies

Upgrade OpenStack Designate to version 22.0.2 or later to address the mDNS handler flaw. Ensure zones with the same name across different pools are reviewed and consolidated if necessary. Monitor DNS query failures and REFUSED responses as potential indicators of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71194. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart