A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. Defenders should assess exposure and prioritize verification of OpenDKIM installations up to 2.11.0. This vulnerability h [truncated]
MEDIUMTrusted Domain ProjectCVE published 2026-09-28
A weakness in OpenDKIM's DKIM signature header selection can lead to an out-of-bounds write, allowing remote attackers to manipulate the argument 'h'. The exploit has been made public, but details on affected versions and remediation are limited. Defenders should assess OpenDKIM installations, especially those exposed to untrusted input, and monitor for potential exploitation attempts. The vulnerability a [truncated]