cbcvebase.

Openstack Designate vulnerabilities

4 known vulnerabilities affecting openstack/designate.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-71193P3CRITICALCVSS 9.6≥ 1.0.0, < 20.0.2≥ 21.0.0, < 21.0.1+1 more2026-08-12
CVE-2026-71193 [CRITICAL] CWE-863 CVE-2026-71193: In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the dupl In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's
nvd
CVE-2026-71194P3MEDIUMCVSS 6.8≥ 1.0.0, < 20.0.2≥ 21.0.0, < 21.0.1+1 more2026-08-12
CVE-2026-71194 [MEDIUM] CWE-669 CVE-2026-71194: In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving re In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is expl
nvd
CVE-2015-5694P4MEDIUMCVSS 6.5v1.0.0v1.0.0.0+1 more2019-11-22
CVE-2015-5694 [MEDIUM] CWE-835 CVE-2015-5694: Designate does not enforce the DNS protocol limit concerning record set sizes Designate does not enforce the DNS protocol limit concerning record set sizes
nvdosv
CVE-2015-5695P4MEDIUMCVSS 6.5v1.0.0.0b1v1.0.0a0+1 more2017-08-31
CVE-2015-5695 [MEDIUM] CWE-400 CVE-2015-5695: Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per d Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted resource record set.
nvdosv
Openstack Designate vulnerabilities | cvebase