CVE-2026-101277
Received Received - Intake

Use of Less Trusted Source in OpenDKIM up to 2.11.0

Vulnerability report for CVE-2026-101277, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use of less trusted source. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendkim to 2.11.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-348 The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects OpenDKIM versions up to 2.11.0. It involves incorrect parsing of DKIM-Signature tag values, such as quoted-string local parts in the i= field or domains ending with a dot. This causes OpenDKIM to misinterpret tag boundaries, leading to errors and false claims in the Authentication-Results header.

Detection Guidance

To detect this vulnerability, inspect OpenDKIM logs for parsing errors or permerror statuses. Check Authentication-Results headers for false rsa-sha1 claims. Test with DKIM signatures containing quoted i= values or d= ending with a dot. Use commands like 'opendkim -V' to verify version and 'grep' to search logs for errors.

Impact Analysis

This flaw disrupts DKIM validation and DMARC alignment for senders using affected OpenDKIM versions. Legitimate emails may be rejected while processed by other verifiers. It also undermines integrity by falsely reporting rsa-sha1 in headers, which is deprecated.

Compliance Impact

This vulnerability may impact compliance with standards requiring secure email authentication and integrity, such as GDPR's data protection measures or HIPAA's secure communication requirements. The flaw causes incorrect DKIM validation, leading to false rsa-sha1 algorithm claims in headers, which undermines integrity and could affect trust in email authenticity. This disruption may interfere with compliance checks relying on DKIM/DMARC alignment for secure email communication.

Mitigation Strategies

Upgrade OpenDKIM to a patched version if available. Temporarily disable DKIM verification for affected domains. Monitor logs for suspicious parsing errors. Consider switching to alternative DKIM verifiers like Rspamd or dkimpy until a fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101277. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart