Skip to content
Threat Feed
medium advisory

Remote Encoding Vulnerability in OpenDMARC

A vulnerability in the OpenDMARC Internationalized Domain Name Handler (up to 1.4.2) allows remote attackers to trigger an encoding error in the opendmarc_policy_query_dmarc function, with public exploit code currently available.

CVE search metadata

CVE search record: CVE-2026-100891. Severity: high. CVSS: 7.3. KEV: no. Product: OpenDMARC (<= 1.4.2). Brief: Remote Encoding Vulnerability in OpenDMARC. Brief link: https://feed.craftedsignal.io/briefs/2026-09-opendmarc-encoding-vulnerability/

The Trusted Domain Project OpenDMARC library, specifically versions up to and including 1.4.2, contains a remote vulnerability within its Internationalized Domain Name (IDN) handling component. The flaw resides in the opendmarc_policy_query_dmarc function within the libopendmarc/opendmarc_policy.c source file. An attacker can remotely trigger an encoding error by sending specially crafted input, which the component fails to process correctly. Public exploit code for this vulnerability has been disclosed, increasing the risk for organizations relying on OpenDMARC for email authentication and DMARC policy enforcement. Given the lack of response from the vendor, users are encouraged to monitor for anomalous email traffic patterns or library crashes that may indicate exploitation attempts.

Impact

Successful exploitation of this vulnerability allows for remote manipulation of the OpenDMARC processing flow. This can lead to service instability, denial of service through encoding-induced errors, or potential bypass of DMARC verification logic, impacting the integrity of email authentication services across affected deployments.

Recommendation

  • Monitor application logs and system stability for services utilizing OpenDMARC (such as mail transfer agents like Postfix or Sendmail) for signs of process crashes or unexpected errors in the opendmarc_policy_query_dmarc function.
  • Evaluate the necessity of IDN handling in current OpenDMARC configurations and disable it if not required for business operations until a security patch is developed.
  • Implement network-level filtering to restrict access to mail infrastructure that relies on vulnerable versions of the OpenDMARC library.
  • Review internal software inventories to identify instances of OpenDMARC versions 1.4.2 or earlier and plan for future migration or patching once a fix becomes available.

Immediate actions

Inventory all servers running OpenDMARC and identify versions 1.4.2 or earlier.

IT Operations 48h

Threat Hunt

Look for frequent crashes or abnormal restart cycles of mail filter processes (e.g., milters) linked to libopendmarc.

medium medium confidence hunt now

Mitigations

Monitor mail infrastructure for service instability.

medium Security Operations

CVE-2026-100891