CVE-2026-71194
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.
CSIRTS triage
- What
- Tenants can manipulate DNS zones belonging to other tenants, enabling denial of service or DNS hijacking.
- Who is affected
- OpenStack Designate deployments allowing multi-tenant DNS zone configuration.
- Urgency
- Critical due to potential for DNS hijacking and cross-tenant denial of service; no exploitation status reported.
- Action
- Apply Debian security update DSA-6452-1 or equivalent patches for CVE-2026-71193 and CVE-2026-71194.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-71194
Get an email if CVE-2026-71194 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownDSA-6452-1 designate - security updatedebian · 2026-08-19
- mediumCVE-2026-71194: In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolv…nvd · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-71194)