{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/trusted-domain-project/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:trusted_domain_project:opendkim:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-100888"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenDKIM (\u003c= 2.11.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","mail-infrastructure","mail-security"],"_cs_type":"advisory","_cs_vendors":["Trusted Domain Project"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-100888) has been identified in the Trusted Domain Project OpenDKIM library up to version 2.11.0. The flaw resides within the dkim_canon_selecthdrs function located in libopendkim/dkim-canon.c, specifically within the DKIM Signature Header Selection component. By manipulating the 'h' argument in a malicious DKIM signature, a remote attacker can trigger an out-of-bounds write. This vulnerability is particularly concerning as public exploit code is already available, potentially enabling remote code execution in applications utilizing the affected library. The vendor was notified of the issue but has not provided a response or a patch as of the reporting date. Defenders should prioritize auditing mail infrastructure utilizing OpenDKIM for potential exploitation attempts or crashes indicating memory corruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to arbitrary code execution or service disruption of mail servers processing DKIM signatures. As OpenDKIM is a widely used library for DKIM verification, the impact is high for any organization relying on it for email authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor for anomalous crashes or unexpected behavior in processes utilizing libopendkim. Given the lack of a vendor patch, consider isolating mail processing components or implementing strict input validation at the edge if possible.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor application logs and system crash reports for memory-related errors originating from mail-handling processes linked against libopendkim.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of OpenDKIM 2.11.0 or earlier in high-exposure segments and consider alternative configurations or temporary hardening measures if upgrading is not an option.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T01:11:33Z","date_published":"2026-09-28T01:11:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opendkim-oob-write/","summary":"A memory corruption vulnerability in the OpenDKIM dkim_canon_selecthdrs function allows remote attackers to trigger an out-of-bounds write via crafted DKIM signature headers.","title":"Remote Out-of-Bounds Write Vulnerability in OpenDKIM","url":"https://feed.craftedsignal.io/briefs/2026-09-opendkim-oob-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Trusted Domain Project","version":"https://jsonfeed.org/version/1.1"}