<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>OpenDMARC (&lt;= 1.4.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/opendmarc--1.4.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 03:11:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/opendmarc--1.4.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Encoding Vulnerability in OpenDMARC</title><link>https://feed.craftedsignal.io/briefs/2026-09-opendmarc-encoding-vulnerability/</link><pubDate>Mon, 28 Sep 2026 03:11:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-opendmarc-encoding-vulnerability/</guid><description>A vulnerability in the OpenDMARC Internationalized Domain Name Handler (up to 1.4.2) allows remote attackers to trigger an encoding error in the opendmarc_policy_query_dmarc function, with public exploit code currently available.</description><content:encoded><![CDATA[<p>The Trusted Domain Project OpenDMARC library, specifically versions up to and including 1.4.2, contains a remote vulnerability within its Internationalized Domain Name (IDN) handling component. The flaw resides in the opendmarc_policy_query_dmarc function within the libopendmarc/opendmarc_policy.c source file. An attacker can remotely trigger an encoding error by sending specially crafted input, which the component fails to process correctly. Public exploit code for this vulnerability has been disclosed, increasing the risk for organizations relying on OpenDMARC for email authentication and DMARC policy enforcement. Given the lack of response from the vendor, users are encouraged to monitor for anomalous email traffic patterns or library crashes that may indicate exploitation attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for remote manipulation of the OpenDMARC processing flow. This can lead to service instability, denial of service through encoding-induced errors, or potential bypass of DMARC verification logic, impacting the integrity of email authentication services across affected deployments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor application logs and system stability for services utilizing OpenDMARC (such as mail transfer agents like Postfix or Sendmail) for signs of process crashes or unexpected errors in the opendmarc_policy_query_dmarc function.</li>
<li>Evaluate the necessity of IDN handling in current OpenDMARC configurations and disable it if not required for business operations until a security patch is developed.</li>
<li>Implement network-level filtering to restrict access to mail infrastructure that relies on vulnerable versions of the OpenDMARC library.</li>
<li>Review internal software inventories to identify instances of OpenDMARC versions 1.4.2 or earlier and plan for future migration or patching once a fix becomes available.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>email-security</category></item></channel></rss>