{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atrusteddomainopendmarc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:trusteddomain:opendmarc:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100891"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenDMARC (\u003c= 1.4.2)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","email-security"],"_cs_type":"advisory","_cs_vendors":["Trusted Domain Project"],"content_html":"\u003cp\u003eThe Trusted Domain Project OpenDMARC library, specifically versions up to and including 1.4.2, contains a remote vulnerability within its Internationalized Domain Name (IDN) handling component. The flaw resides in the opendmarc_policy_query_dmarc function within the libopendmarc/opendmarc_policy.c source file. An attacker can remotely trigger an encoding error by sending specially crafted input, which the component fails to process correctly. Public exploit code for this vulnerability has been disclosed, increasing the risk for organizations relying on OpenDMARC for email authentication and DMARC policy enforcement. Given the lack of response from the vendor, users are encouraged to monitor for anomalous email traffic patterns or library crashes that may indicate exploitation attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for remote manipulation of the OpenDMARC processing flow. This can lead to service instability, denial of service through encoding-induced errors, or potential bypass of DMARC verification logic, impacting the integrity of email authentication services across affected deployments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor application logs and system stability for services utilizing OpenDMARC (such as mail transfer agents like Postfix or Sendmail) for signs of process crashes or unexpected errors in the opendmarc_policy_query_dmarc function.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of IDN handling in current OpenDMARC configurations and disable it if not required for business operations until a security patch is developed.\u003c/li\u003e\n\u003cli\u003eImplement network-level filtering to restrict access to mail infrastructure that relies on vulnerable versions of the OpenDMARC library.\u003c/li\u003e\n\u003cli\u003eReview internal software inventories to identify instances of OpenDMARC versions 1.4.2 or earlier and plan for future migration or patching once a fix becomes available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T03:11:49Z","date_published":"2026-09-28T03:11:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opendmarc-encoding-vulnerability/","summary":"A vulnerability in the OpenDMARC Internationalized Domain Name Handler (up to 1.4.2) allows remote attackers to trigger an encoding error in the opendmarc_policy_query_dmarc function, with public exploit code currently available.","title":"Remote Encoding Vulnerability in OpenDMARC","url":"https://feed.craftedsignal.io/briefs/2026-09-opendmarc-encoding-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:trusteddomain:opendmarc:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}