CVE-2026-100889
Received Received - Intake

Off-by-One in OpenDKIM Decoder Function

Vulnerability report for CVE-2026-100889, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendkim to 2.11.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-193 A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100889 is an off-by-one error in OpenDKIM's libopendkim library, specifically in the dkim_qp_decode() function in util.c. It occurs when processing a DKIM-Signature header with a long quoted-printable i= tag, causing a stack-allocated buffer to be overwritten. This leads to an out-of-bounds read, potentially causing crashes or undefined behavior.

Detection Guidance

To detect this vulnerability, monitor for crashes or undefined behavior in OpenDKIM services when processing DKIM-Signature headers with long quoted-printable i= tags. Use AddressSanitizer or similar tools to detect out-of-bounds reads in the dkim_qp_decode function. Check logs for segmentation faults or memory corruption errors in OpenDKIM processes.

Impact Analysis

This vulnerability can be exploited remotely without authentication by sending a specially crafted email. It may cause crashes or undefined behavior in systems using vulnerable OpenDKIM versions, potentially disrupting email services or allowing further exploitation.

Mitigation Strategies

Immediately update OpenDKIM to the latest patched version that fixes the off-by-one error in dkim_qp_decode. If an update is unavailable, apply the manual fix by changing the bounds check from q <= end to q < end in util.c and ensure a NUL terminator is added before returning. Temporarily disable DKIM verification for untrusted emails if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart