CVE-2026-101278
Received Received - Intake

OpenDMARC Origin Validation Error via PSL Wildcard Handler

Vulnerability report for CVE-2026-101278, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101278 is a weakness in OpenDMARC versions up to 1.4.2 where incorrect organizational domain computation occurs when using wildcard entries in the Public Suffix List. The flaw causes OpenDMARC to stop counting labels at the wildcard match, resulting in an organizational domain that is one label short of the correct registrable domain. This allows relaxed DKIM alignment to incorrectly accept DKIM signatures from sibling hosts under the same wildcard suffix, bypassing DMARC's rejection policy.

Detection Guidance

To detect this vulnerability, check if your OpenDMARC version is 1.4.2 or earlier. Run: opendmarc --version. If using a package manager, check with: rpm -qa | grep opendmarc or dpkg -l | grep opendmarc. Inspect logs for DKIM alignment failures or unexpected DMARC pass results from sibling hosts under wildcard suffixes.

Impact Analysis

This vulnerability allows attackers who control a host under the same wildcard suffix as the victim to bypass DMARC's rejection policy. This is particularly feasible on shared cloud infrastructure like AWS EC2. The impact includes potential email spoofing or phishing attacks due to incorrect DKIM alignment validation.

Compliance Impact

This vulnerability could potentially impact compliance with standards requiring email authentication and integrity, such as GDPR's requirement for secure data processing or HIPAA's email security rules. By allowing DKIM signature bypass through incorrect organizational domain computation, it may weaken email security controls that these regulations rely on to protect sensitive data.

Mitigation Strategies

Upgrade OpenDMARC to the latest patched version if available. If no patch exists, disable wildcard PSL handling in OpenDMARC configuration or switch to a non-wildcard PSL entry. Monitor DKIM alignment failures and restrict DMARC policies to reject unauthorized mail from sibling hosts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101278. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart