Hi Yaook users,

OpenStack published two CVEs for designate.

One is a vulnerability in OpenStack Designate zone scheduling. An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected.

The other CVE is a related vulnerability in the Designate mDNS handler during triage. The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP.

The following images are vulnerable:

If this image is used in your cluster for the designate deployment, the cluster is vulnerable.

The fixed image has been built in a private pipeline[2] which has been published alongside the advisory[1] to prove the image provenance.

We recommend to add a YAOOK_OP_VERSIONS_OVERRIDE[3] variable to your Designate operator container to pull the image before the YAOOK comprehensive release is ready.

operator:
    extraEnv:
    - name: YAOOK_OP_VERSIONS_OVERRIDE
    value: |
        {
            "registry.yaook.cloud/yaook/designate-2024.1": "registry.yaook.cloud/yaook/designate-2024.1:1.0.29",
            "registry.yaook.cloud/yaook/designate-2024.2": "registry.yaook.cloud/yaook/designate-2024.2:1.0.29",
            "registry.yaook.cloud/yaook/designate-2025.1": "registry.yaook.cloud/yaook/designate-2025.1:1.0.29",
            "registry.yaook.cloud/yaook/designate-2025.2": "registry.yaook.cloud/yaook/designate-2025.2:1.0.29",
            "registry.yaook.cloud/yaook/designate-2026.1": "registry.yaook.cloud/yaook/designate-2026.1:1.0.29"
        }

More info can be found in our security advisory[1].

Regards
Stefan


[1] https://yaook.cloud/security-advisories-cve-2026-71193-71194/
[2] https://gitlab.com/yaook-security/images/designate/-/pipelines/2746847469
[3] https://docs.yaook.cloud/user/references/env-reference.html#envvar-YAOOK_OP_VERSIONS_OVERRIDE

-- 
Stefan Hoffmann
DevOps Engineer

Cloud&Heat Technologies GmbH
Königsbrücker Straße 96 | 01099 Dresden
+49 351 479 367 36
stefan.hoffmann@cloudandheat.com | www.cloudandheat.com

Green, Open, Efficient.
Ihr Cloud-Service- und Cloud-Technologie-Provider aus Dresden.
https://www.cloudandheat.com/

Commercial Register: District Court Dresden
Register Number: HRB 30549
VAT ID No.: DE281093504
Managing Director: Nicolas Röhrs
Authorized signatory: Dr. Marius Feldmann