Description
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Validation Flaw
Action: Patch Now
AI Analysis

Impact

A flaw exists in the policy.c component of Trusted Domain Project OpenDMARC versions up to 1.4.2 that fails to correctly validate unsafe equivalence in input. This flaw allows an attacker to craft input that bypasses validation, potentially influencing policy handling or other processing. The vulnerability is exploitable remotely, and an exploit has been published.

Affected Systems

Trusted Domain Project’s OpenDMARC, affecting all releases through 1.4.2. The issue is located in the Domain Handler component’s policy.c file. Users should verify whether their deployment runs a version in this range.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The exploit has been published and the attack can be launched remotely, suggesting realistic attack potential. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk remains non‑negligible. Organizations relying on OpenDMARC for email authentication and policy enforcement should treat the flaw as moderate but actionable.

Generated by OpenCVE AI on September 28, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenDMARC to version 1.4.3 or later, which contains the policy.c validation fix.
  • If immediate upgrade is not possible, modify configuration or policy files to avoid input paths that may trigger the vulnerable code, such as simplifying domain patterns or disabling affected features.
  • Apply network‑level controls to restrict remote access to the Domain Handler interface until the patch is deployed and policies are verified.

Generated by OpenCVE AI on September 28, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in input
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-1289
CWE-20
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T08:30:08.347Z

Reserved: 2026-09-27T11:33:01.551Z

Link: CVE-2026-101015

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T09:17:05.180

Modified: 2026-09-28T15:15:33.930

Link: CVE-2026-101015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:30:15Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input

  • CWE-20

    Improper Input Validation