PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-101014 Trusted Domain Project CVE debrief

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. The function opendmarc_util_cleanup in libopendmarc/opendmarc_util.c is affected by an off-by-one error. The attack may be initiated remotely. A patch is available: b3b1da9264bc80324094a27c71e7369bdedc62ae. This vulnerability allows remote attackers to potentially exploit the off-by-one error, which could lead to security issues. Defenders should assess exposure and prioritize patching to prevent potential remote attacks.

Vendor
Trusted Domain Project
Product
OpenDMARC
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders responsible for OpenDMARC installations should assess exposure and prioritize patching to prevent potential remote attacks. This includes reviewing OpenDMARC versions, applying patches if necessary, and monitoring for potential security issues. Security teams and vulnerability management teams should also be aware of this vulnerability and take appropriate actions.

Why it matters

CVE-2026-101014 is a medium-severity vulnerability in OpenDMARC that allows remote attackers to exploit an off-by-one error. Defenders should prioritize patching OpenDMARC installations to prevent potential attacks. Evidence is limited on affected versions and exploitation.

  • Verify OpenDMARC version and apply patch if vulnerable
  • Monitor for potential remote attacks on OpenDMARC
  • Assess exposure of OpenDMARC installations

Technical summary

The opendmarc_util_cleanup function in libopendmarc/opendmarc_util.c of OpenDMARC is vulnerable to an off-by-one error. This issue allows remote attackers to potentially exploit the vulnerability. A patch (b3b1da9264bc80324094a27c71e7369bdedc62ae) has been provided to address this issue. The vulnerability is considered medium-severity and defenders should prioritize patching OpenDMARC installations to prevent potential remote attacks. The affected component is part of the DMARC Record Parser, which could be manipulated remotely.

Defensive priority

Defenders should prioritize patching OpenDMARC installations to prevent potential remote attacks.

Recommended defensive actions

  • Apply the patch (b3b1da9264bc80324094a27c71e7369bdedc62ae) to OpenDMARC installations
  • Verify OpenDMARC version is not vulnerable (less than or equal to 1.4.2)
  • Monitor for potential remote attacks on OpenDMARC
  • Review OpenDMARC configurations for exposure
  • Assess the security posture of OpenDMARC installations
  • Track and verify patch deployment across the environment
  • Document verification and patching efforts for future reference

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and exploitation is limited. Evidence is based on CVE and NVD data, with limited further details available. Defenders should verify OpenDMARC versions and apply patches if vulnerable. The patch provided (b3b1da9264bc80324094a27c71e7369bdedc62ae) addresses this issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-101014 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-101014

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-101014 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101014

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.