Hi,
The following vulnerabilities were published for opendmarc.
CVE-2026-100890[0]:
| A flaw has been found in Trusted Domain Project OpenDMARC up to
| 1.4.2. Affected by this vulnerability is the function
| opendmarc_spf_ipv6_explode in the library
| libopendmarc/opendmarc_spf.c of the component SPF Parser. This
| manipulation of the argument cp causes null pointer dereference. It
| is possible to initiate the attack remotely. The exploit has been
| published and may be used. The vendor was contacted early about this
| disclosure but did not respond in any way.
CVE-2026-100891[1]:
| A vulnerability has been found in Trusted Domain Project OpenDMARC
| up to 1.4.2. Affected by this issue is the function
| opendmarc_policy_query_dmarc in the library
| libopendmarc/opendmarc_policy.c of the component Internationalized
| Domain Name Handler. Such manipulation leads to encoding error. It
| is possible to launch the attack remotely. The exploit has been
| disclosed to the public and may be used. The vendor was contacted
| early about this disclosure but did not respond in any way.
CVE-2026-101014[2]:
| A vulnerability was detected in Trusted Domain Project OpenDMARC up
| to 1.4.2. Affected by this vulnerability is the function
| opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c
| of the component DMARC Record Parser. Performing a manipulation
| results in off-by-one. The attack may be initiated remotely. The
| exploit is now public and may be used. The patch is named
| b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is
| recommended to deploy a patch.
CVE-2026-101015[3]:
| A flaw has been found in Trusted Domain Project OpenDMARC up to
| 1.4.2. Affected by this issue is some unknown functionality of the
| file policy.c of the component Domain Handler. Executing a
| manipulation can lead to improper validation of unsafe equivalence
| in input. The attack may be launched remotely. The exploit has been
| published and may be used. The vendor was contacted early about this
| disclosure but did not respond in any way.
CVE-2026-101016[4]:
| A vulnerability has been found in Trusted Domain Project OpenDMARC
| up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc
| in the library libopendmarc/opendmarc_policy.c. The manipulation of
| the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of
| exceptional conditions. Remote exploitation of the attack is
| possible. The exploit has been disclosed to the public and may be
| used. The vendor was contacted early about this disclosure but did
| not respond in any way.
CVE-2026-101017[5]:
| A vulnerability was found in Trusted Domain Project OpenDMARC up to
| 1.4.2. This vulnerability affects the function strcasecmp in the
| library libopendmarc/opendmarc_policy.c. The manipulation results in
| handling of exceptional conditions. The attack can be executed
| remotely. The exploit has been made public and could be used. The
| vendor was contacted early about this disclosure but did not respond
| in any way.
CVE-2026-101278[6]:
| A weakness has been identified in Trusted Domain Project OpenDMARC
| up to 1.4.2. This affects the function opendmarc_get_tld of the file
| libopendmarc/opendmarc_tld.c : of the component PSL Wildcard
| Handler. Executing a manipulation can lead to origin validation
| error. The attack may be launched remotely. The exploit has been
| made available to the public and could be used for attacks. The
| vendor was contacted early about this disclosure but did not respond
| in any way.
CVE-2026-101279[7]:
| A security vulnerability has been detected in Trusted Domain Project
| OpenDMARC up to 1.4.2. This impacts an unknown function of the file
| libopendmarc/opendmarc_policy.c of the component DMARC Parser. The
| manipulation of the argument pct leads to integer overflow. Remote
| exploitation of the attack is possible. The exploit has been
| disclosed publicly and may be used. The vendor was contacted early
| about this disclosure but did not respond in any way.
CVE-2026-101280[8]:
| A vulnerability was detected in Trusted Domain Project OpenDMARC up
| to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of
| the component Multi-Record Set Handler. The manipulation results in
| authentication bypass by spoofing. The attack can be executed
| remotely. The exploit is now public and may be used. The vendor was
| contacted early about this disclosure but did not respond in any
| way.
CVE-2026-101281[9]:
| A flaw has been found in Trusted Domain Project OpenDMARC up to
| 1.4.2. Affected by this vulnerability is the function
| opendmarc_sp2_find_mailfrom_domain of the file
| libopendmarc/opendmarc_spf.c of the component SPF Macro Handler.
| This manipulation causes improper authentication. The attack is
| possible to be carried out remotely. The exploit has been published
| and may be used. Patch name:
| c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the
| recommended action to fix this issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-100890
https://www.cve.org/CVERecord?id=CVE-2026-100890
[1] https://security-tracker.debian.org/tracker/CVE-2026-100891
https://www.cve.org/CVERecord?id=CVE-2026-100891
[2] https://security-tracker.debian.org/tracker/CVE-2026-101014
https://www.cve.org/CVERecord?id=CVE-2026-101014
[3] https://security-tracker.debian.org/tracker/CVE-2026-101015
https://www.cve.org/CVERecord?id=CVE-2026-101015
[4] https://security-tracker.debian.org/tracker/CVE-2026-101016
https://www.cve.org/CVERecord?id=CVE-2026-101016
[5] https://security-tracker.debian.org/tracker/CVE-2026-101017
https://www.cve.org/CVERecord?id=CVE-2026-101017
[6] https://security-tracker.debian.org/tracker/CVE-2026-101278
https://www.cve.org/CVERecord?id=CVE-2026-101278
[7] https://security-tracker.debian.org/tracker/CVE-2026-101279
https://www.cve.org/CVERecord?id=CVE-2026-101279
[8] https://security-tracker.debian.org/tracker/CVE-2026-101280
https://www.cve.org/CVERecord?id=CVE-2026-101280
[9] https://security-tracker.debian.org/tracker/CVE-2026-101281
https://www.cve.org/CVERecord?id=CVE-2026-101281
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore