Description
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote exploitation via IDN encoding error
Action: Assess Impact
AI Analysis

Impact

A defect exists in the opendmarc_policy_query_dmarc function of OpenDMARC’s Internationalized Domain Name handler, allowing an attacker to manipulate input encoding and trigger an error. The exploitation can be carried out from a remote source and is publicly disclosed, indicating that execution is feasible. The failure to process IDN correctly may lead to further weaknesses in the system, potentially exposing sensitive configuration or allowing denial of service, though definitive data on escalation is not provided in the description.

Affected Systems

Trusted Domain Project’s OpenDMARC library versions up to and including 1.4.2 are impacted. Systems running these versions with IDN handling enabled are vulnerable.

Risk and Exploitability

The CVSS score of 6.9 places this flaw in the medium severity range, suggesting that while it may not provide full remote code execution, it does create a pathway for disruptive attacks. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, implying that large‑scale exploitation is not actively reported yet. However, the attack is described as possible to launch remotely, and the public disclosure of the exploit indicates that attackers could attempt to use this vector. Organizations should evaluate the attack surface and consider the potential impact of an IDN parsing error in their mail flow infrastructure.

Generated by OpenCVE AI on September 28, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for vendor updates and apply any released patches that address the IDN encoding flaw.
  • If upgrading is not immediately feasible, disable Internationalized Domain Name handling in OpenDMARC’s configuration to avoid the vulnerable code path identified as CWE-172.
  • Restrict network access to the OpenDMARC component to trusted hosts and apply firewall rules to limit exposure to external connections.

Generated by OpenCVE AI on September 28, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-172
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T00:15:14.678Z

Reserved: 2026-09-27T07:55:14.732Z

Link: CVE-2026-100891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T01:16:28.367

Modified: 2026-09-28T01:16:28.367

Link: CVE-2026-100891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T02:30:17Z

Weaknesses