« Back to list

Trusteddomain

Trusteddomain Opendmarc: vulnerabilities and CVEs

Trusteddomain Opendmarc has 16 published vulnerabilities, 10 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs16
Last 12 months10
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-101281Medium (5.5)0.41%—Sep 28, 2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF…
CVE-2026-101280Medium (5.5)0.40%—Sep 28, 2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication…
CVE-2026-101279Medium (5.5)0.32%—Sep 28, 2026
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of…
CVE-2026-101278Low (2.1)0.13%—Sep 28, 2026
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a…
CVE-2026-101017Medium (5.5)0.32%—Sep 28, 2026
A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of…
CVE-2026-101016Medium (5.5)0.32%—Sep 28, 2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument…
CVE-2026-101015Medium (5.5)0.29%—Sep 28, 2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to…
CVE-2026-101014Medium (5.5)0.31%—Sep 28, 2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC…
CVE-2026-100891Medium (5.5)0.29%—Sep 27, 2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component…
CVE-2026-100890Medium (5.5)0.37%—Sep 27, 2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser.…
CVE-2024-25768High (7.5)0.73%—Feb 26, 2024
OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
CVE-2021-34555High (7.5)2.7%—Jun 10, 2021
OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.
CVE-2020-12460Critical (9.8)3.7%—Jul 27, 2020
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC…
CVE-2020-12272Medium (5.3)2.2%—Apr 27, 2020
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation…
CVE-2019-20790Critical (9.8)2.6%—Apr 27, 2020
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
CVE-2019-16378Critical (9.8)2.5%—Sep 17, 2019
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application9
  2. T1499.004 Application or System Exploitation4
  3. T1078 Valid Accounts2
  4. T1059 Command and Scripting Interpreter1
  5. T1195.002 Compromise Software Supply Chain1
  6. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.