CVE-2026-101279
Received Received - Intake

Integer Overflow in OpenDMARC DMARC Parser

Vulnerability report for CVE-2026-101279, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
trusted_domain_project opendmarc to 1.4.2 (inc)
rspamd rspamd 4.1.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101279 involves improper handling of the DMARC 'pct' tag in OpenDMARC and Rspamd. The 'pct' value specifies the percentage of messages to which a DMARC policy applies. In OpenDMARC, an integer overflow occurs when 'pct' values outside 0-100 are converted to a 32-bit unsigned integer before validation. Values like 4294967296 wrap around to 0, causing incorrect policy enforcement. In Rspamd, negative 'pct' values are clamped to 0, disabling policy enforcement entirely.

Both vulnerabilities allow attackers to manipulate DMARC policy enforcement by influencing the 'pct' value, either bypassing intended policies or disabling them completely.

Detection Guidance

To detect this vulnerability, inspect DMARC records for invalid 'pct' values outside 0-100 range. Check OpenDMARC logs for integer overflow errors or 'permerror' messages. For Rspamd, look for negative 'pct' values being clamped to 0. Use tools like dig or nslookup to query DMARC records and verify the 'pct' field.

Impact Analysis

This vulnerability allows attackers to bypass or disable DMARC email authentication policies. If exploited, forged emails under a 'p=reject' policy could be delivered, increasing the risk of phishing or spoofing attacks. Systems relying on DMARC for email security may fail to enforce intended policies, compromising email integrity.

Compliance Impact

This vulnerability could impact compliance with regulations requiring email security measures, such as GDPR (data protection) or HIPAA (healthcare data). Failure to enforce DMARC policies may result in unauthorized email access, violating confidentiality and integrity requirements. Organizations must remediate this issue to maintain compliance.

Mitigation Strategies

Update OpenDMARC to the latest version that validates 'pct' before integer conversion. For Rspamd, ensure negative 'pct' values are rejected. Review DMARC records to confirm 'pct' values are within 0-100. Monitor logs for policy enforcement bypass attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101279. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart