CVE-2026-101281: Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarcsp2findmailfromdomain of the file libopendmarc/opendmarcspf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trusted Domain Project OpenDMARCto a version that resolves this vulnerability.Patch c48a74c758677fc5272a73eff15ffdbf8afda1a6
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Deployments of Trusted Domain Project OpenDMARC up to version 1.4.2 should be prioritized, particularly where the SPF Macro Handler is in use. The issue can be exploited remotely without stated authentication or user interaction requirements.
What is known about exploitability?
The vulnerability has a low attack complexity and is reachable over the network. A public exploit has been published and may be used.
What should teams do to remediate the issue?
Apply patch c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying the patch is the recommended remediation.