Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch. | |
| Title | Trusted Domain Project OpenDMARC DMARC Record opendmarc_util.c opendmarc_util_cleanup off-by-one | |
| First Time appeared |
Trusted Domain Project
Trusted Domain Project opendmarc |
|
| Weaknesses | CWE-189 CWE-193 |
|
| CPEs | cpe:2.3:a:trusted_domain_project:opendmarc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Trusted Domain Project
Trusted Domain Project opendmarc |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T08:15:13.249Z
Reserved: 2026-09-27T11:32:56.615Z
Link: CVE-2026-101014
No data.
Status : Received
Published: 2026-09-28T09:17:03.893
Modified: 2026-09-28T09:17:03.893
Link: CVE-2026-101014
No data.
OpenCVE Enrichment
Updated: 2026-09-28T09:30:14Z