Hi Yaook users,
OpenStack published two CVEs for designate.
One is a vulnerability in OpenStack Designate zone scheduling. An authenticated tenant can bypass zone ownership checks by scheduling a zone to a different pool, creating overlapping zones that hijack or deny service to another tenant's DNS records. Any user with the default create_zone policy can exploit this when the AttributeFilter scheduler is enabled. Only deployments using the AttributeFilter scheduler with multiple pools are affected.
The other CVE is a related vulnerability in the Designate mDNS handler during triage. The mDNS handler performs pool-blind record lookups that fail when colliding zones exist across pools, causing deterministic DNS query failures. The NOTIFY handler path is reachable via unauthenticated UDP.
The following images are vulnerable:
If this image is used in your cluster for the designate deployment, the cluster is vulnerable.
The fixed image has been built in a private pipeline[2] which has been published alongside the advisory[1] to prove the image provenance.
We recommend to add a YAOOK_OP_VERSIONS_OVERRIDE[3] variable to your Designate operator container to pull the image before the YAOOK comprehensive release is ready.
operator:
extraEnv:
- name: YAOOK_OP_VERSIONS_OVERRIDE
value: |
{
"registry.yaook.cloud/yaook/designate-2024.1": "registry.yaook.cloud/yaook/designate-2024.1:1.0.29",
"registry.yaook.cloud/yaook/designate-2024.2": "registry.yaook.cloud/yaook/designate-2024.2:1.0.29",
"registry.yaook.cloud/yaook/designate-2025.1": "registry.yaook.cloud/yaook/designate-2025.1:1.0.29",
"registry.yaook.cloud/yaook/designate-2025.2": "registry.yaook.cloud/yaook/designate-2025.2:1.0.29",
"registry.yaook.cloud/yaook/designate-2026.1": "registry.yaook.cloud/yaook/designate-2026.1:1.0.29"
}
More info can be found in our security advisory[1].
Regards
Stefan
[1] https://yaook.cloud/security-advisories-cve-2026-71193-71194/
[2]
https://gitlab.com/yaook-security/images/designate/-/pipelines/2746847469
[3]
https://docs.yaook.cloud/user/references/env-reference.html#envvar-YAOOK_OP_VERSIONS_OVERRIDE
-- Stefan Hoffmann DevOps Engineer Cloud&Heat Technologies GmbH Königsbrücker Straße 96 | 01099 Dresden +49 351 479 367 36 stefan.hoffmann@cloudandheat.com | www.cloudandheat.com Green, Open, Efficient. Ihr Cloud-Service- und Cloud-Technologie-Provider aus Dresden. https://www.cloudandheat.com/ Commercial Register: District Court Dresden Register Number: HRB 30549 VAT ID No.: DE281093504 Managing Director: Nicolas Röhrs Authorized signatory: Dr. Marius Feldmann