CVE-2026-100895
Received Received - Intake

Null Pointer Dereference in Trusted Domain Project OpenARC

Vulnerability report for CVE-2026-100895, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
trusteddomainproject openarc to 1.0.0.Beta1 (inc)
trusteddomainproject libopenarc to 1.0.0.Beta1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100895 is a NULL pointer dereference flaw in Trusted Domain Project OpenARC up to version 1.0.0.Beta1. The vulnerability occurs in the libopenarc library's arc_parse_canon_t function when processing ARC-Message-Signature headers with a c=relaxed value lacking a body canonicalisation specification. This causes a segmentation fault when a NULL pointer is passed to arc_name_to_code, crashing the ARC verifier.

Detection Guidance

To detect CVE-2026-100895, monitor for crashes in OpenARC's libopenarc library, particularly when processing ARC-Message-Signature headers with c=relaxed values lacking a body canonicalisation. Check logs for segmentation faults in the arc_parse_canon_t() function. Use AddressSanitizer during compilation to identify NULL pointer dereferences.

Impact Analysis

This vulnerability allows remote attackers to crash the ARC verifier by sending a maliciously crafted email, causing a denial of service. Since ARC is used to verify authentication results across email forwarding hops, legitimate emails may also trigger the crash during verification, disrupting mail processing.

Compliance Impact

This vulnerability causes a denial of service by crashing the ARC verifier through a NULL pointer dereference. While it does not directly expose data, service disruption could impact systems handling regulated data under GDPR or HIPAA by failing to process or verify emails properly.

Mitigation Strategies

Upgrade OpenARC to version 1.0.0.Beta0 or later immediately. This version includes fixes for the NULL pointer dereference in libopenarc. If upgrading is not possible, apply the NULL check patch to arc_name_to_code() and modify arc_parse_canon_t() to default to simple body canonicalisation when none is specified.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100895. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart