What is CVE-2026-71194?
CVE-2026-71194 is a vulnerability in the mDNS handler of OpenStack Designate before version 22.0.2. When two zones with the same name exist across different pools, the handler performs pool-blind lookups, leading to a deterministic error that returns REFUSED for all DNS queries. Affected systems should be updated to version 22.0.2 immediately to prevent service disruption.
Azərbaycanca: CVE-2026-71194, OpenStack Designate-in 22.0.2-dən əvvəlki versiyalarında mDNS handler-də tapılan boşluqdur. Müxtəlif pool-larda eyni adlı iki zona olduqda, sorğulara 'pool-blind lookup' edən handler deterministik səhv nəticəsində bütün DNS sorğularına REFUSED cavabı qaytarır. Təsirlənən sistemlərdə xidmətin dayanması riski var, ən qısa zamanda 22.0.2 versiyasına yenilənməlidir.
Related CVEs
link basis: shared vendor: OpenStack
FAQ2
In which component of OpenStack Designate was CVE-2026-71194 found, and what is its primary impact?
The vulnerability was found in the mDNS handler. When two zones with the same name exist across different pools, the handler performs pool-blind lookups, causing a deterministic error that returns REFUSED for all DNS queries, leading to a risk of service disruption.
Which version should be upgraded to in order to mitigate CVE-2026-71194?
It is recommended to upgrade to OpenStack Designate version 22.0.2 immediately to mitigate the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.