CVE-2026-101017

Summary

A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
Trusted Domain ProjectOpenDMARC1.4.0affected
Trusted Domain ProjectOpenDMARC1.4.1affected
Trusted Domain ProjectOpenDMARC1.4.2affected

Weaknesses

  • CWE-755: Handling of Exceptional Conditions

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References