---
id: CVE-2026-100888
title: A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0
summary: >-
  A weakness has been identified in Trusted Domain Project OpenDKIM up to
  2.11.0. This affects the function dkim_canon_selecthdrs of the file
  libopendkim/dkim-canon.c of the component DKIM Signature Header Selection.
  Executing a manipulati…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-787
vendor: Trusted Domain Project
product: OpenDKIM
affected:
  - OpenDKIM 2.0
  - OpenDKIM 2.1
  - OpenDKIM 2.2
  - OpenDKIM 2.3
  - OpenDKIM 2.4
  - OpenDKIM 2.5
  - OpenDKIM 2.6
  - OpenDKIM 2.7
  - OpenDKIM 2.8
  - OpenDKIM 2.9
  - OpenDKIM 2.10
  - OpenDKIM 2.11.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T00:16:32.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100888'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-100888'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/917015'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410837'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410837/cti'
    label: cna@vuldb.com
  - url: 'https://weitongli.com/share/opendkim-h-tag-oob-write.html'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T23:59:58.081Z'
---

## Overview

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
