VYPR

Designate

by OpenStack

pypi: designate

Source repositories

CVEs (5)

  • CVE-2026-71193CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter…

  • CVE-2015-5694MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.02

    Designate does not enforce the DNS protocol limit concerning record set sizes

  • CVE-2015-5695MedAug 31, 2017
    risk 0.42cvss 6.5epss 0.02

    Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (infinite loop) via a…

  • CVE-2026-71194MedAug 12, 2026
    risk 0.37cvss 6.8epss 0.01

    In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return…

  • CVE-2023-6725MedMar 15, 2024
    risk 0.36cvss 5.5epss 0.00

    An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive…