PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100890 Trusted Domain Project CVE debrief

A vulnerability was found in OpenDMARC up to 1.4.2, affecting the opendmarc_spf_ipv6_explode function in libopendmarc/opendmarc_spf.c. This flaw causes a null pointer dereference when manipulating the cp argument in the SPF Parser component. The attack can be initiated remotely. The exploit has been published but vendor response is unknown. The vulnerability allows remote attackers to cause null pointer dereferences, potentially leading to denial-of-service conditions. Defenders need to verify OpenDMARC versions and assess exposure. Remediation priority is medium due to the CVSS score of 5.5.

Vendor
Trusted Domain Project
Product
OpenDMARC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders responsible for OpenDMARC deployments should assess exposure and verify versions. Security teams monitoring SPF parser usage and configurations should also review this vulnerability. Additionally, operators of affected systems should prioritize remediation due to the potential for denial-of-service conditions. Vulnerability management teams should track this vulnerability and ensure that affected systems are updated or mitigated.

Why it matters

CVE-2026-100890 is a medium-severity vulnerability in OpenDMARC's SPF parser, allowing remote null pointer dereference attacks. Defenders should verify versions, assess exposure, and monitor for exploit attempts.

  • Remote attackers can exploit this vulnerability to cause null pointer dereferences
  • Successful exploitation may lead to denial-of-service conditions
  • Defenders need to verify OpenDMARC versions and assess exposure
  • Remediation priority is medium due to the CVSS score of 5.5

Technical summary

The opendmarc_spf_ipv6_explode function in OpenDMARC's libopendmarc/opendmarc_spf.c is vulnerable to null pointer dereference attacks. This occurs when the cp argument is manipulated in the SPF Parser component. The vulnerability allows remote attacks and has a CVSS score of 5.5. Successful exploitation may lead to denial-of-service conditions. Defenders should prioritize verifying OpenDMARC versions and assessing exposure, as the vulnerability allows remote attacks through SPF parsing. The vulnerability is a result of improper handling of IPv6 addresses in the SPF parser.

Defensive priority

Defenders should prioritize verifying OpenDMARC versions and assessing exposure, as the vulnerability allows remote attacks through SPF parsing.

Recommended defensive actions

  • Verify OpenDMARC version and assess exposure
  • Review SPF parser configurations and usage
  • Monitor for exploit attempts and anomalies
  • Apply vendor patches or updates if available
  • Implement compensating controls for exposed systems
  • Conduct asset inventory to identify potentially affected systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE and NVD records provide details on the vulnerability in OpenDMARC's SPF parser. Vendor response to disclosure is unknown. The vulnerability has been publicly disclosed and may be used by attackers. There is no information on in-the-wild exploitation. Defenders should verify OpenDMARC versions and assess exposure to this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100890 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100890

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100890 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100890

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.