Description
A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the strcasecmp function of OpenDMARC’s policy parser, where exceptional conditions are incorrectly handled. A crafted comparison can cause the library to execute unintended operations, potentially leading to crashes or other anomalous behavior. The attack vector is remote, and a public exploit is available, meaning the weakness can be leveraged without local access.

Affected Systems

Trusted Domain Project OpenDMARC versions up to 1.4.2 are affected. Any installation of this software that has not been upgraded beyond this release remains vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed on the CISA KEV catalog. Because the exploit is publicly available and the attack can be performed remotely, operators must treat the risk as significant until a patch is applied.

Generated by OpenCVE AI on September 28, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any OpenDMARC update newer than version 1.4.2 as soon as it is released.
  • If a patch is not yet available, monitor OpenDMARC logs for unexpected crashes or abnormal policy parsing failures, and investigate any incidents promptly.
  • Consider isolating the OpenDMARC process from untrusted external mail sources until a fix is applied by using separate mail handling or quarantine solutions.

Generated by OpenCVE AI on September 28, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 28 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional condition
First Time appeared Trusted Domain Project
Trusted Domain Project opendmarc
Weaknesses CWE-755
CPEs cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:*
Vendors & Products Trusted Domain Project
Trusted Domain Project opendmarc
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Trusted Domain Project Opendmarc
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T12:43:56.403Z

Reserved: 2026-09-27T11:33:10.549Z

Link: CVE-2026-101017

cve-icon Vulnrichment

Updated: 2026-09-28T12:43:52.246Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T09:17:05.503

Modified: 2026-09-28T15:15:33.930

Link: CVE-2026-101017

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-28T09:00:10Z

Links: CVE-2026-101017 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:00:17Z

Weaknesses
  • CWE-476

    NULL Pointer Dereference

  • CWE-755

    Improper Handling of Exceptional Conditions