Sceawere

Vulnerability Detail

CVE-2026-100895UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenARC Null Pointer Dereference

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
6h ago
Vendor
Trusted Domain Project
Product
OpenARC
Attack Type
NULL Pointer Dereference
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.0.0.Beta0 is recommended to address this issue. Upgrading the affected component is advised.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T02:17:19.437Z",
  "pubdate": "2026-09-28T02:17:19.437Z",
  "executiveSummary": "A critical security vulnerability has been identified in Trusted Domain Project OpenARC, specifically within the libopenarc library.\nThe vulnerability is classified as a null pointer dereference occurring within the arc_parse_canon_t function.\nThis flaw allows remote attackers to trigger a crash in the affected process, potentially leading to a Denial of Service (DoS) condition.\nAffected systems include versions of OpenARC up to 1.0.0.Beta1.\nThe vulnerability is considered high risk due to the availability of public exploit code, which lowers the barrier for attackers to remotely trigger the flaw.\nExploitation does not inherently require prior authentication, making remote exploitation feasible if the application processes untrusted ARC (Authenticated Received Chain) data.",
  "technicalDetails": "The vulnerability resides in the arc_parse_canon_t function located within the source file libopenarc/arc-canon.c.\nThe root cause is an improper validation of input parameters or internal state during the canonicalization process, leading to the application attempting to dereference a null pointer during the parsing of ARC header fields.\nIn the context of ARC processing, the arc_parse_canon_t function is responsible for parsing and canonicalizing headers to ensure consistent authentication results.\nWhen a specifically crafted ARC header or sequence is provided to the library, the logic fails to correctly handle the null state, causing the memory access violation.\nThe attack flow begins when an attacker sends a message containing a malformed ARC header to an email server or relay utilizing the libopenarc component.\nUpon receipt, the library parses the header, triggering the flaw in arc_parse_canon_t. The attempt to access an object at a null memory address results in an immediate segmentation fault or process termination.\nSince libopenarc is often integrated into mail transfer agents (MTAs), a successful exploit forces the termination of the MTA worker process or the entire service, effectively denying service to legitimate users.\nThe vulnerability is remotely exploitable as the parser handles external input provided via SMTP streams.\nNo specific privileges are required by the attacker, as the vulnerability is triggered by the natural processing of incoming email traffic.\nPost-exploitation impact is primarily limited to process crashes; however, depending on the architecture of the deployment, this may lead to complete service unavailability."
}
CVE-2026-100895: OpenARC Null Pointer Dereference (MEDIUM Severity, CVSS: 5.3) | Sceawere