CVE-2026-101014
Received Received - Intake

Off-by-One in OpenDMARC DMARC Record Parser

Vulnerability report for CVE-2026-101014, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-193 A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101014 is an off-by-one error in the OpenDMARC library's opendmarc_util_cleanup function. It occurs when processing DMARC TXT records, where a string of exactly 32 characters fills a buffer without space for a null terminator. This causes the buffer to be unterminated, leading to a stack buffer overflow when strlen() reads past allocated memory.

Detection Guidance

To detect this vulnerability, check if your OpenDMARC version is 1.4.2 or earlier. Use commands like 'opendmarc -v' or inspect package versions on Linux (e.g., 'rpm -qa | grep opendmarc' or 'dpkg -l | grep opendmarc'). Monitor logs for crashes or unusual behavior in the milter process.

Impact Analysis

The vulnerability can crash the OpenDMARC milter process or cause undefined behavior in the policy parser. This may disrupt mail delivery. An attacker can trigger it remotely by sending an email with a crafted domain in the From header, requiring no user interaction beyond that.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling remote attacks that disrupt mail delivery or cause undefined behavior in the policy parser. A buffer overflow in OpenDMARC may lead to crashes or unauthorized memory access, which could compromise data integrity or availability. GDPR requires protecting personal data integrity and availability, while HIPAA mandates secure handling of electronic protected health information. A successful exploit could violate these requirements by disrupting services or exposing sensitive data.

Mitigation Strategies

Immediately update OpenDMARC to a patched version using the provided patch (commit b3b1da9264bc80324094a27c71e7369bdedc62ae). Alternatively, apply the fix manually by editing libopendmarc/opendmarc_util.c to change the buffer length check from '>' to '>=' in the opendmarc_util_cleanup function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart