CVE-2026-101014
7.3 HIGHpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-189, CWE-193
Public exploit & PoC references
All references
- https://github.com/trusteddomainproject/OpenDMARC/commit/b3b1da9264bc80324094a27c71e7369bdedc62ae
- https://github.com/trusteddomainproject/OpenDMARC/pull/188
- https://github.com/trusteddomainproject/OpenDMARC/pull/344
- https://vuldb.com/cve/CVE-2026-101014
- https://vuldb.com/submit/917100
- https://vuldb.com/vuln/410884
- https://vuldb.com/vuln/410884/cti
- https://weitongli.com/share/opendmarc-cleanup-off-by-one.html
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100889
- MEDIUMCVE-2026-101279
- UNSCOREDCVE-2026-18460
- MEDIUMCVE-2026-83600PoC
- MEDIUMCVE-2026-93018PoC
- LOWCVE-2026-94030PoC
- MEDIUMCVE-2026-94090PoC
- LOWCVE-2026-95958PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.