Description
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Upgrade
AI Analysis

Impact

A flaw has been reported in the Trusted Domain Project OpenDMARC up to version 1.4.2. The vulnerability resides in the function opendmarc_spf_ipv6_explode within the SPF Parser component. The function manipulates the argument cp without proper null‑pointer checks, which leads to a dereference of a null pointer. The effect of this error is that an attacker who can supply crafted input may cause unintended code paths or system crashes, providing an opportunity for remote code execution or denial of service. The weakness is a classic null‑pointer dereference (CWE‑476) as well as an improper resource cleanup (CWE‑404).

Affected Systems

The affected product is Trusted Domain Project OpenDMARC, specifically any release up to and including 1.4.2. Systems running these versions of OpenDMARC that process SPF records—common in mail server stacks such as Postfix, Exim, or Microsoft Exchange when using OpenDMARC for DMARC/SPF checks—are vulnerable. The exact CPE string for the product is cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*.*

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the public data. However, the advisory notes that an exploit has been published and is likely deployable, so the risk to exposed systems is significant. No listing in the CISA KEV catalog does not reduce the importance of applying a patch. The attack vector is inferred to be remote, as the description states the flaw can be triggered remotely through malformed SPF input. The typical exploitation path would involve an attacker crafting a malicious SPF query that causes the OpenDMARC library to dereference a null pointer within the SPF IPv6 handling routine.

Generated by OpenCVE AI on September 28, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDMARC to version 1.4.3 or later, which removes the null pointer dereference bug.
  • If an upgrade is not immediately possible, limit the use of the SPF parser to internal or trusted networks and block SPF validation requests from untrusted sources until the patch is applied.
  • In environments that can be reconfigured, temporarily disable SPF processing or replace the OpenDMARC library with an alternative that does not contain the vulnerability until a vendor fix is available.

Generated by OpenCVE AI on September 28, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode null pointer dereference
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-404
CWE-476
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T00:00:12.540Z

Reserved: 2026-09-27T07:55:10.374Z

Link: CVE-2026-100890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T01:16:28.047

Modified: 2026-09-28T01:16:28.047

Link: CVE-2026-100890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T01:30:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-476

    NULL Pointer Dereference