CVE-2026-101015

Summary

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
Trusted Domain ProjectOpenDMARC1.4.0affected
Trusted Domain ProjectOpenDMARC1.4.1affected
Trusted Domain ProjectOpenDMARC1.4.2affected

Weaknesses

  • CWE-1289: Improper Validation of Unsafe Equivalence in Input
  • CWE-20: Improper Input Validation

References