CVE-2026-101017
Received Received - Intake

Remote Exception Handling Flaw in OpenDMARC

Vulnerability report for CVE-2026-101017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101017 is a vulnerability in OpenDMARC versions up to 1.4.2 where improper handling of DMARC policy discovery occurs when a subdomain has a malformed DMARC record with an incorrect version tag like v=DMARC2 or v=DMARC1.0. Instead of discarding these invalid records as per RFC 7489, OpenDMARC responds with a 'permerror' and stops processing, preventing the enforcement of the parent domain's strict rejection policy. This allows attackers to spoof emails from subdomains by bypassing security measures.

Detection Guidance

To detect this vulnerability, check OpenDMARC versions 1.4.2 and earlier for improper handling of DMARC policy discovery. Inspect DMARC records for subdomains with incorrect version tags like v=DMARC2 or v=DMARC1.0. Use commands like 'dig TXT _dmarc.example.com' to review records and verify if OpenDMARC halts processing due to malformed tags.

Impact Analysis

This vulnerability could allow attackers to send spoofed emails from subdomains of a domain using OpenDMARC, bypassing email authentication and potentially tricking recipients into trusting malicious messages. It undermines the intended security of DMARC policies, especially those set to reject unauthorized emails (sp=reject).

Compliance Impact

This vulnerability could impact compliance with standards requiring email authentication and integrity, such as GDPR's data protection principles or HIPAA's secure communication requirements. By allowing attackers to spoof emails from subdomains, it undermines trust in email authenticity, which may violate regulations mandating secure and verifiable communication channels.

Mitigation Strategies

Immediately update OpenDMARC to a patched version that discards invalid DMARC version tags and continues policy discovery per RFC 7489. If an update is unavailable, manually review and correct DMARC records for all subdomains to ensure proper version tags (v=DMARC1). Temporarily enforce stricter email authentication policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart