Sceawere

Vulnerability Detail

CVE-2026-101278UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC PSL Wildcard Validation Error

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
6h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T01:16:43.787Z",
  "pubdate": "2026-09-29T01:16:43.787Z",
  "executiveSummary": "A critical vulnerability has been identified in the PSL Wildcard Handler component of Trusted Domain Project OpenDMARC, affecting versions up to 1.4.2.\nThe vulnerability resides within the opendmarc_get_tld function in the file libopendmarc/opendmarc_tld.c, leading to improper origin validation.\nThis flaw allows remote, unauthenticated attackers to bypass domain-based security controls by exploiting errors in Public Suffix List (PSL) wildcard processing.\nSuccessful exploitation results in an origin validation error, which may permit malicious entities to spoof domain identities or circumvent DMARC-based authentication policies.\nThe vulnerability is currently subject to public exploit availability, posing an immediate risk to organizations relying on OpenDMARC for email authentication.\nThe vendor has remained unresponsive to disclosure attempts, necessitating proactive defensive measures by end-users.",
  "technicalDetails": "The vulnerability is located in the opendmarc_get_tld function within libopendmarc/opendmarc_tld.c, which is responsible for parsing and identifying the Top-Level Domain (TLD) and effective domain from a given hostname using the Public Suffix List (PSL).\nThe root cause is a logic error in the PSL Wildcard Handler mechanism. When processing domains that involve wildcard entries (e.g., *.example.com), the function fails to correctly constrain or validate the domain boundaries under specific configurations or malicious input formats.\nAn attacker can exploit this by crafting a specific, malformed, or specially nested domain string that forces the opendmarc_get_tld function to incorrectly identify the TLD. By miscalculating the organizational boundary, the parser may return an overly broad or incorrect domain context.\nThis failure in origin validation fundamentally undermines the integrity of DMARC (Domain-based Message Authentication, Reporting, and Conformance) checks. In an email processing pipeline, OpenDMARC relies on the output of this function to determine if the 'From' domain aligns with the DKIM and SPF records. If the boundary is misidentified, the validation engine may incorrectly associate a malicious or spoofed domain with a trusted organizational parent, allowing the malicious mail to pass DMARC checks that should have failed.\nThe attack is remote and does not require prior authentication or elevated privileges, as it targets the fundamental parsing logic of incoming mail headers or domain metadata. Because the exploit is publicly available, an attacker can automate the submission of specially crafted domains that target the parsing flaw.\nPost-exploitation, the impact is primarily the degradation of email authentication trust. Because the DMARC validation process is bypassed, an attacker can successfully deliver phishing, spam, or spoofed content that appears to originate from a legitimate or trusted domain. This effectively nullifies the security protections provided by OpenDMARC, allowing for successful domain impersonation and the potential compromise of downstream mail users. The vulnerability persists across all deployments of the affected versions until the parsing logic is patched or the input is sanitized at an earlier stage in the pipeline."
}
CVE-2026-101278: OpenDMARC PSL Wildcard Validation Error (MEDIUM Severity, CVSS: 4.3) | Sceawere