Description
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption that could lead to remote code execution
Action: Apply Patch
AI Analysis

Impact

A flaw exists in the opendmarc_util_cleanup routine of OpenDMARC’s DMARC Record parser, where an off‑by‑one error causes an improperly sized buffer during cleanup of authority and policy strings. The vulnerability can be triggered by providing malformed DMARC records, potentially overwriting adjacent memory and allowing an attacker to influence program behaviour. The result may be a denial of service or, in the worst case, arbitrary code execution if the overwritten bytes control critical data such as function pointers or return addresses. The weak code path is rooted in improper bounds checking and buffer management, reflecting the weaknesses identified by CWE‑189 and CWE‑193.

Affected Systems

OpenDMARC versions up to and including 1.4.2 shipped by the Trusted Domain Project are affected. Older releases prior to 1.4.2 are not known to contain the flaw and newer releases contain the patch supplied by commit b3b1da9264bc80324094a27c71e7369bdedc62ae.

Risk and Exploitability

The CVSS score of 6.9 positions the vulnerability as medium‑to‑high severity, and its remote exploitation potential is confirmed by the description. Although the EPSS score is not available, the public disclosure of the exploit and the fact that the flaw can be triggered via remote DMARC records raise concern. The vulnerability is not listed in the CISA KEV catalog, but the available evidence suggests that exploitation is feasible and the risk to systems that process DMARC records is non‑negligible.

Generated by OpenCVE AI on September 28, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDMARC to the patched release that incorporates commit b3b1da9264bc80324094a27c71e7369bdedc62ae, or apply the patch directly if a newer binary is unavailable.
  • If the patch cannot be applied immediately, consider temporarily disabling DMARC record parsing or replacing the OpenDMARC binary with a known safe version that predates the vulnerability.
  • Enable detailed logging for DMARC failures and monitor for anomalous parsing activity, as early detection can alert administrators to attempts to exploit the flaw before remediation is complete.

Generated by OpenCVE AI on September 28, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 28 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Title Trusted Domain Project OpenDMARC DMARC Record opendmarc_util.c opendmarc_util_cleanup off-by-one
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-189
CWE-193
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T12:43:21.470Z

Reserved: 2026-09-27T11:32:56.615Z

Link: CVE-2026-101014

cve-icon Vulnrichment

Updated: 2026-09-28T12:43:17.655Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T09:17:03.893

Modified: 2026-09-28T15:15:33.930

Link: CVE-2026-101014

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-28T08:15:13Z

Links: CVE-2026-101014 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses