CVE-2026-101015
Received Received - Intake

Improper Input Validation in OpenDMARC Domain Handler

Vulnerability report for CVE-2026-101015, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)
trusted_domain_project opendmarc to 1.4 (inc)
trusted_domain_project opendmarc to 1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101015 is a flaw in OpenDMARC versions up to 1.4.2 where a missing IDNA ToASCII/UTS-46 mapping step in the DMARC Author Domain extraction process allows attackers to bypass DMARC policies. By using Unicode characters like fullwidth full stop (U+FF0E) in the From domain, which normalizes to a plain-ASCII domain, attackers can forge unsigned messages that bypass DMARC protections (p=reject or p=quarantine) without needing DKIM keys or DNS control.

Detection Guidance

To detect CVE-2026-101015, check OpenDMARC versions including 1.4.2-1+deb12u1 and earlier 1.4.x or 1.3.x releases. Monitor email logs for DMARC policy failures or unexpected message deliveries. Use IDNA ToASCII/UTS-46 validation tests on From domains to identify Unicode character bypass attempts.

Impact Analysis

This vulnerability allows attackers to send fraudulent emails that appear to come from legitimate domains protected by DMARC. Even if DMARC is configured with reject or quarantine policies, these forged emails may bypass security checks and reach recipients. This could lead to phishing attacks, email fraud, or unauthorized access to sensitive information.

Mitigation Strategies

Apply IDNA ToASCII with UTS-46 processing to the extracted Author Domain before _dmarc query alignment as per RFC 7489 section 6.6.1. Ensure full separator and compatibility character mappings are handled. Update OpenDMARC to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101015. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart