Impact
A flaw exists in the policy.c component of Trusted Domain Project OpenDMARC versions up to 1.4.2 that fails to correctly validate unsafe equivalence in input. This flaw allows an attacker to craft input that bypasses validation, potentially influencing policy handling or other processing. The vulnerability is exploitable remotely, and an exploit has been published.
Affected Systems
Trusted Domain Project’s OpenDMARC, affecting all releases through 1.4.2. The issue is located in the Domain Handler component’s policy.c file. Users should verify whether their deployment runs a version in this range.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The exploit has been published and the attack can be launched remotely, suggesting realistic attack potential. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk remains non‑negligible. Organizations relying on OpenDMARC for email authentication and policy enforcement should treat the flaw as moderate but actionable.
OpenCVE Enrichment