PatchSiren cyber security CVE debrief
CVE-2026-101014 Trusted Domain Project CVE debrief
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. The function opendmarc_util_cleanup in libopendmarc/opendmarc_util.c is affected by an off-by-one error. The attack may be initiated remotely. A patch is available: b3b1da9264bc80324094a27c71e7369bdedc62ae. This vulnerability allows remote attackers to potentially exploit the off-by-one error, which could lead to security issues. Defenders should assess exposure and prioritize patching to prevent potential remote attacks.
- Vendor
- Trusted Domain Project
- Product
- OpenDMARC
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for OpenDMARC installations should assess exposure and prioritize patching to prevent potential remote attacks. This includes reviewing OpenDMARC versions, applying patches if necessary, and monitoring for potential security issues. Security teams and vulnerability management teams should also be aware of this vulnerability and take appropriate actions.
Why it matters
CVE-2026-101014 is a medium-severity vulnerability in OpenDMARC that allows remote attackers to exploit an off-by-one error. Defenders should prioritize patching OpenDMARC installations to prevent potential attacks. Evidence is limited on affected versions and exploitation.
- Verify OpenDMARC version and apply patch if vulnerable
- Monitor for potential remote attacks on OpenDMARC
- Assess exposure of OpenDMARC installations
Technical summary
The opendmarc_util_cleanup function in libopendmarc/opendmarc_util.c of OpenDMARC is vulnerable to an off-by-one error. This issue allows remote attackers to potentially exploit the vulnerability. A patch (b3b1da9264bc80324094a27c71e7369bdedc62ae) has been provided to address this issue. The vulnerability is considered medium-severity and defenders should prioritize patching OpenDMARC installations to prevent potential remote attacks. The affected component is part of the DMARC Record Parser, which could be manipulated remotely.
Defensive priority
Defenders should prioritize patching OpenDMARC installations to prevent potential remote attacks.
Recommended defensive actions
- Apply the patch (b3b1da9264bc80324094a27c71e7369bdedc62ae) to OpenDMARC installations
- Verify OpenDMARC version is not vulnerable (less than or equal to 1.4.2)
- Monitor for potential remote attacks on OpenDMARC
- Review OpenDMARC configurations for exposure
- Assess the security posture of OpenDMARC installations
- Track and verify patch deployment across the environment
- Document verification and patching efforts for future reference
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and exploitation is limited. Evidence is based on CVE and NVD data, with limited further details available. Defenders should verify OpenDMARC versions and apply patches if vulnerable. The patch provided (b3b1da9264bc80324094a27c71e7369bdedc62ae) addresses this issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101014 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101014
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101014 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101014
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/trusteddomainproject/OpenDMARC/commit/b3b1da9264bc80324094a27c71e7369bdedc62ae
-
Source reference
Unverified legacy reference
URL: https://github.com/trusteddomainproject/OpenDMARC/pull/188
-
Source reference
Unverified legacy reference
URL: https://github.com/trusteddomainproject/OpenDMARC/pull/344
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-101014
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/917100
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410884
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/410884/cti
-
Source reference
Unverified legacy reference
URL: https://weitongli.com/share/opendmarc-cleanup-off-by-one.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.