PT-2026-99737 · Opendmarc · Opendmarc

·

CVE-2026-100890

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenDMARC versions prior to 1.4.3
Description A flaw in the SPF Parser component exists within the opendmarc spf ipv6 explode() function located in the libopendmarc/opendmarc spf.c library. A remote attacker can trigger a null pointer dereference, which occurs when a program attempts to read from a memory address that is null, by manipulating the cp argument.
Recommendations Update to a version newer than 1.4.2. As a temporary mitigation, restrict the processing of SPF records that may trigger the opendmarc spf ipv6 explode() function.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100890

Affected Products

Opendmarc