---
id: CVE-2026-101014
title: A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2
summary: >-
  A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2.
  Affected by this vulnerability is the function opendmarc_util_cleanup in the
  library libopendmarc/opendmarc_util.c of the component DMARC Record Parser.
  Perfor…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-189
  - CWE-193
vendor: Trusted Domain Project
product: OpenDMARC
affected:
  - OpenDMARC 1.4.0
  - OpenDMARC 1.4.1
  - OpenDMARC 1.4.2
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T09:17:03.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101014'
references:
  - url: >-
      https://github.com/trusteddomainproject/OpenDMARC/commit/b3b1da9264bc80324094a27c71e7369bdedc62ae
    label: cna@vuldb.com
  - url: 'https://github.com/trusteddomainproject/OpenDMARC/pull/188'
    label: cna@vuldb.com
  - url: 'https://github.com/trusteddomainproject/OpenDMARC/pull/344'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-101014'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/917100'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410884'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410884/cti'
    label: cna@vuldb.com
  - url: 'https://weitongli.com/share/opendmarc-cleanup-off-by-one.html'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T09:06:28.562Z'
---

## Overview

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
