Designate OpenStack Designate

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in OpenStack Designate.

By the Year

In 2026 there have been 2 vulnerabilities in OpenStack Designate with an average score of 8.2 out of ten.

Year Vulnerabilities Average Score
2026 2 8.20

It may take a day or so for new Designate vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent OpenStack Designate Security Vulnerabilities

OpenStack Designate mDNS Pool-Blind Lookup (before 22.0.2)
CVE-2026-71194 6.8 - Medium - August 12, 2026

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.

Incorrect Resource Transfer Between Spheres

OpenStack Designate before 22.0.1 Cross-Tenant DNS Hijack via AttributeFilter
CVE-2026-71193 9.6 - Critical - August 12, 2026

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for OpenStack Designate or by OpenStack? Click the Watch button to subscribe.

OpenStack
Vendor

subscribe