Sceawere

Vulnerability Detail

CVE-2026-101277UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDKIM Tag Tokenizer Improper Trust

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Trusted Domain Project
Product
OpenDKIM
Attack Type
Use of Less Trusted Source
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use of less trusted source. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-29T00:17:03.010Z",
  "pubdate": "2026-09-29T00:17:03.010Z",
  "executiveSummary": "A security vulnerability has been identified in the Trusted Domain Project OpenDKIM, specifically within the Tag Tokenizer component. The flaw, affecting versions up to 2.11.0, involves the use of less trusted sources during the processing of DKIM tags, which can be triggered via remote manipulation.\nThis vulnerability is classified as an improper trust boundary issue, potentially allowing an attacker to influence the internal state or parsing logic of the DKIM verification process. Because this component is critical to email authentication, the exploitation of this flaw could lead to bypasses in DKIM verification mechanisms or potential memory corruption scenarios depending on the input handling.\nThe vulnerability is currently public, and exploit code exists, posing an immediate risk to systems utilizing OpenDKIM. The vendor remained unresponsive following the initial disclosure. Attackers can initiate this exploit remotely without requiring prior authentication, making it a significant concern for mail transfer agents (MTAs) and security gateways relying on OpenDKIM for integrity checks.",
  "technicalDetails": "The vulnerability resides within the dkim_process_set function located in dkim.c. This function is a core component of the Tag Tokenizer, responsible for interpreting and assigning values to DKIM tag fields during the parsing of DKIM-Signature headers.\nThe root cause of this vulnerability is the improper validation or sanitization of data sources when the library processes tag-value pairs. By injecting crafted tag inputs, an attacker can force the application to consume data from less trusted sources, bypassing intended security checks. This manipulation occurs because the function does not strictly enforce trust boundaries when handling external tag input, allowing for a logical flaw in the assignment phase.\nThe attack flow begins when an attacker sends a crafted email containing a malformed or malicious DKIM-Signature header. The OpenDKIM library, upon receiving this header, passes the input to the dkim_process_set function. Because the tokenizer fails to validate the provenance or the structure of the input effectively, the function proceeds to process the malicious payload. This exploitation does not require the attacker to have administrative privileges or existing sessions with the server; the exploit is purely network-based, targeting the parsing engine of the receiving MTA.\nThe technical impact of this vulnerability involves the potential compromise of the email authentication chain. By tricking the parser into using less trusted input, an attacker may influence subsequent cryptographic verification steps. This could lead to a scenario where a forged signature is incorrectly validated or where the parser enters an undefined state, potentially causing a crash or allowing for arbitrary code execution if the input is further processed in a way that triggers heap or stack overflows. The public availability of exploit material increases the risk, as it allows threat actors to automate the identification and targeting of vulnerable mail servers. Given the lack of a vendor patch, the system remains in a perpetual state of exposure to remote exploitation, requiring immediate defensive intervention to prevent message forgery or denial-of-service conditions in the mail infrastructure."
}
CVE-2026-101277: OpenDKIM Tag Tokenizer Improper Trust (MEDIUM Severity, CVSS: 6.5) | Sceawere