CVE-2026-101014
Last modified
CVE-2026-101014 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser.
Description
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Trusted Domain Project | OpenDMARC | 1.4.0; 1.4.1; 1.4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-101014?
How severe is CVE-2026-101014?
How do I fix CVE-2026-101014?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-101009A vulnerability was determined in aaPanel BaoTa up to 11.8.0…8.4
- CVE-2026-10101ACM/MCE assisted-service writes raw referenced pull-secret c…6.3
- CVE-2026-101010A vulnerability was identified in aaPanel BaoTa up to 11.8.0…4.7
- CVE-2026-101011A security flaw has been discovered in aaPanel BaoTa up to 1…4.7
- CVE-2026-101012A weakness has been identified in mathurvishal CloudClassroo…7.3
- CVE-2026-101013A security vulnerability has been detected in mathurvishal C…7.3
- CVE-2026-101015A flaw has been found in Trusted Domain Project OpenDMARC up…7.3
- CVE-2026-101016A vulnerability has been found in Trusted Domain Project Ope…6.5
- CVE-2026-101017A vulnerability was found in Trusted Domain Project OpenDMAR…6.5
- CVE-2026-101018A vulnerability was determined in dayrui XunruiCMS up to 4.7…4.7
- CVE-2026-10103Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…4.3
- CVE-2026-101032navi through 2.24.0 fails to properly escape cheatsheet vari…7
Are you affected by CVE-2026-101014?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
