PT-2026-102415 · Opendmarc · Opendmarc
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenDMARC versions prior to 1.4.3
Description
A weakness exists in the PSL Wildcard Handler component within the
opendmarc get tld() function of the libopendmarc/opendmarc tld.c file. A remote attacker can perform a manipulation that leads to an origin validation error.Recommendations
Update to a version newer than 1.4.2.
As a temporary mitigation, restrict the use of the
opendmarc get tld() function.Exploit
Fix
Origin Validation Error
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opendmarc