CVE-2026-101014

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-189CWE-193

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0x870x4k3r@pepetheshneine

    5/7 OpenDMARC got fresh disclosures too. Don't inflate them: CVE-2026-101014 is a remotely triggerable parser bug, but Red Hat classifies the impact as DoS, not RCE. CVE-2026-101016 also affects policy parsing. https://access.redhat.com/security/cve/CVE-2026-101014

    1000022
    28 followersView on X

Explore more