PT-2026-99738 · Opendmarc · Opendmarc

·

CVE-2026-100891

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenDMARC versions prior to 1.4.3
Description An issue exists in the Internationalized Domain Name Handler component within the opendmarc policy query dmarc() function located in the libopendmarc/opendmarc policy.c library. A remote attacker can manipulate this function to cause an encoding error.
Recommendations Update OpenDMARC to a version newer than 1.4.2. As a temporary mitigation, restrict the use of the opendmarc policy query dmarc() function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100891

Affected Products

Opendmarc