CVE-2026-100890Medium· 5.3▾ SunlitA flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation o…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
OpenDMARC 1.4.0OpenDMARC 1.4.1OpenDMARC 1.4.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100891High· 7.3Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error
CVE-2026-93312Medium· 4.3A flaw has been found in Freedesktop Poppler 26.07.0
CVE-2026-92417Medium· 6.5A vulnerability was found in Open5GS up to 2.8.0
CVE-2026-92413Medium· 4.3A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9
CVE-2026-91780Low· 3.3A weakness has been identified in GNU Binutils 2.47
CVE-2026-91781Low· 3.3A security vulnerability has been detected in GNU Binutils 2.47