Trusted Domain · Openrc · CVE-2026-100895
**Name of the Vulnerable Software and Affected Versions**
Trusted Domain Project OpenARC versions prior to 1.0.0.Beta0
**Description**
A security flaw in the `libopenarc` component allows for a remote attack. The issue resides in the `arc parse canon t()` function within the `libopenarc/arc-canon.c` library, where specific manipulation leads to a null pointer dereference, a condition where the software attempts to read from a memory address that is null, typically resulting in a crash.
**Recommendations**
Update to version 1.0.0.Beta0.
As a temporary mitigation, restrict access to the `arc parse canon t()` function within the `libopenarc` component.