Sceawere

Vulnerability Detail

CVE-2026-100891UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC IDN Encoding Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
7h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Encoding Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T01:16:28.367Z",
  "pubdate": "2026-09-28T01:16:28.367Z",
  "executiveSummary": "A critical encoding vulnerability has been identified within the Internationalized Domain Name (IDN) handler of OpenDMARC, affecting all versions up to 1.4.2.\nThe vulnerability resides in the opendmarc_policy_query_dmarc function, which fails to correctly sanitize or process specific IDN inputs.\nThis flaw allows remote, unauthenticated attackers to trigger encoding errors, which can potentially lead to unpredictable application behavior or service disruption.\nGiven that the exploit has been disclosed publicly and the vendor has remained unresponsive to disclosure efforts, the risk to production environments is elevated.\nSuccessful exploitation allows an attacker to manipulate the policy query process remotely, potentially bypassing DMARC security checks or inducing a denial-of-service condition through malformed input triggers.",
  "technicalDetails": "The vulnerability is located in libopendmarc/opendmarc_policy.c within the opendmarc_policy_query_dmarc function. The root cause is an improper handling of Internationalized Domain Names (IDN) during the policy query evaluation process. When the library encounters maliciously crafted or malformed IDN inputs, it fails to handle the encoding conversion or validation routines correctly, resulting in an encoding error.\nThe attack flow initiates when an attacker sends a specially crafted email or query containing an internationalized domain string designed to trigger the flaw during the DMARC policy lookup phase. The opendmarc_policy_query_dmarc function, tasked with parsing and validating domain information against DMARC records, receives this input. Due to the lack of robust sanitization or error-handling mechanisms for anomalous IDN sequences, the function enters an erroneous state.\nExploitation does not require prior authentication or privileged access. Because the component processes incoming network-level data for DMARC verification, it is exposed to remote manipulation. By submitting an email with a domain name that forces an encoding mismatch or buffer miscalculation within the IDN handler, the attacker can cause the process to crash or produce an erroneous result in the DMARC policy determination.\nThe impact of this vulnerability is significant, as it degrades the integrity of the email authentication chain. By inducing an encoding error, an attacker may force the DMARC implementation to fail open or fail closed depending on the system configuration, effectively bypassing security policies or causing a localized denial-of-service on the mail server. The public availability of exploit information increases the likelihood of opportunistic attacks targeting mail transfer agents (MTAs) utilizing this library."
}
CVE-2026-100891: OpenDMARC IDN Encoding Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere