CVE-2026-100891
Received Received - Intake

OpenDMARC Internationalized Domain Name Encoding Error

Vulnerability report for CVE-2026-100891, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-172 The product does not properly encode or decode the data, resulting in unexpected values.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenDMARC, a tool for enforcing DMARC policies on email domains. It occurs when OpenDMARC fails to properly convert internationalized domain names (IDNs) from UTF-8 to ASCII format before checking DMARC policies. This allows attackers to bypass email authentication by sending forged messages that appear legitimate due to IDN homoglyphs or misalignment.

Detection Guidance

To detect CVE-2026-100891, check if your OpenDMARC version is 1.4.2 or earlier. Run 'opendmarc --version' to verify. Inspect email headers for DMARC failures on internationalized domain names (IDNs). Test by sending an email from an IDN domain and check if DMARC policy is bypassed.

Impact Analysis

This vulnerability allows remote attackers to bypass DMARC email authentication policies without authentication or user interaction. It enables policy bypass, homoglyph phishing, and denial of validation for legitimate IDN senders. Attackers can send forged emails that evade DMARC enforcement, potentially leading to phishing attacks or unauthorized email access.

Compliance Impact

This vulnerability in OpenDMARC allows attackers to bypass DMARC policies for internationalized domain names (IDNs) by exploiting encoding errors. This could lead to unauthorized email spoofing, which may violate data integrity and authentication requirements in GDPR and HIPAA. Specifically, the flaw enables homoglyph phishing and policy bypass, undermining secure email communication standards required for compliance.

Mitigation Strategies

Upgrade OpenDMARC to a patched version that includes IDNA ToASCII conversion before DMARC lookups. If no patch is available, implement manual IDNA conversion in the DMARC policy query process. Monitor for policy bypass attempts on IDN domains.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100891. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart