PatchSiren cyber security CVE debrief
CVE-2026-100890 Trusted Domain Project CVE debrief
A vulnerability was found in OpenDMARC up to 1.4.2, affecting the opendmarc_spf_ipv6_explode function in libopendmarc/opendmarc_spf.c. This flaw causes a null pointer dereference when manipulating the cp argument in the SPF Parser component. The attack can be initiated remotely. The exploit has been published but vendor response is unknown. The vulnerability allows remote attackers to cause null pointer dereferences, potentially leading to denial-of-service conditions. Defenders need to verify OpenDMARC versions and assess exposure. Remediation priority is medium due to the CVSS score of 5.5.
- Vendor
- Trusted Domain Project
- Product
- OpenDMARC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for OpenDMARC deployments should assess exposure and verify versions. Security teams monitoring SPF parser usage and configurations should also review this vulnerability. Additionally, operators of affected systems should prioritize remediation due to the potential for denial-of-service conditions. Vulnerability management teams should track this vulnerability and ensure that affected systems are updated or mitigated.
Why it matters
CVE-2026-100890 is a medium-severity vulnerability in OpenDMARC's SPF parser, allowing remote null pointer dereference attacks. Defenders should verify versions, assess exposure, and monitor for exploit attempts.
- Remote attackers can exploit this vulnerability to cause null pointer dereferences
- Successful exploitation may lead to denial-of-service conditions
- Defenders need to verify OpenDMARC versions and assess exposure
- Remediation priority is medium due to the CVSS score of 5.5
Technical summary
The opendmarc_spf_ipv6_explode function in OpenDMARC's libopendmarc/opendmarc_spf.c is vulnerable to null pointer dereference attacks. This occurs when the cp argument is manipulated in the SPF Parser component. The vulnerability allows remote attacks and has a CVSS score of 5.5. Successful exploitation may lead to denial-of-service conditions. Defenders should prioritize verifying OpenDMARC versions and assessing exposure, as the vulnerability allows remote attacks through SPF parsing. The vulnerability is a result of improper handling of IPv6 addresses in the SPF parser.
Defensive priority
Defenders should prioritize verifying OpenDMARC versions and assessing exposure, as the vulnerability allows remote attacks through SPF parsing.
Recommended defensive actions
- Verify OpenDMARC version and assess exposure
- Review SPF parser configurations and usage
- Monitor for exploit attempts and anomalies
- Apply vendor patches or updates if available
- Implement compensating controls for exposed systems
- Conduct asset inventory to identify potentially affected systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE and NVD records provide details on the vulnerability in OpenDMARC's SPF parser. Vendor response to disclosure is unknown. The vulnerability has been publicly disclosed and may be used by attackers. There is no information on in-the-wild exploitation. Defenders should verify OpenDMARC versions and assess exposure to this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100890 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100890
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100890 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100890
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-100890
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/917188
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410840
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410840/cti
-
Source reference
Unverified legacy reference
URL: https://weitongli.com/share/opendmarc-ip6-wild-pointer.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.