Description
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-27
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Exploit
Action: Apply Patch
AI Analysis

Impact

The OpenDKIM library, a component of the Trusted Domain Project, contains an off‑by‑one error in the dkim_qp_decode function of util.c. A malicious actor can craft a DKIM query that causes the decoder to read or write outside the bounds of its buffer. This memory corruption could lead to application instability, denial of service, or, in the worst case, arbitrary code execution if the underlying platform is vulnerable to buffer overflow exploitation.

Affected Systems

The vulnerability affects Trusted Domain Project’s OpenDKIM version 2.11.0 and earlier. Any system running one of these releases and processing DKIM messages is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. No EPSS score is reported, and the issue is not listed in the CISA KEV catalog. The exploit is publicly available and can be performed remotely, and the vendor has not issued a response, which increases the likelihood that active exploitation may occur. Organizations should consider these factors when prioritizing remediation.

Generated by OpenCVE AI on September 28, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDKIM to a release that includes the fixed decoder routine (e.g., 2.11.1 or later).
  • If no newer release is available, mitigate by restricting or disabling the decoder for untrusted input until a patch is applied.
  • Implement monitoring of DKIM decoding logs and set alerts for abnormal decoding activity to detect attempted exploitation.

Generated by OpenCVE AI on September 28, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one
First Time appeared Trusted Domain Project
Trusted Domain Project opendkim
Weaknesses CWE-189
CWE-193
CPEs cpe:2.3:a:trusted_domain_project:opendkim:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendkim
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendkim
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-27T23:45:16.286Z

Reserved: 2026-09-27T07:35:55.983Z

Link: CVE-2026-100889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T00:16:32.647

Modified: 2026-09-28T00:16:32.647

Link: CVE-2026-100889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T01:30:06Z

Weaknesses