rootpwn

medium · CVSS v3 4.3

CVE-2026-101278

A flaw in OpenDMARC's PSL Wildcard Handler allows remote manipulation of origin validation. The issue exists in versions up to 1.4.2 and can

Overview

A flaw in OpenDMARC's PSL Wildcard Handler allows remote manipulation of origin validation. The issue exists in versions up to 1.4.2 and can cause incorrect domain validation. Defenders should update or patch the affected component.

Description

A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The vulnerability can lead to a breach of the Integrity and Availability of email domain validation, potentially allowing attackers to spoof email origins. This undermines the authenticity of email communications. Email security teams and administrators of affected OpenDMARC deployments are directly impacted.

Remediation

Upgrade OpenDMARC to version 1.4.3 or later where the PSL Wildcard Handler has been fixed. If upgrade is not immediately possible, disable the PSL wildcard feature or restrict the TLD list to a trusted subset. Monitor logs for anomalous origin validation failures.

Risk context

The CVSS score of 4.3 indicates medium risk; no EPSS data is available. The public availability of exploit code increases the likelihood of exploitation, so timely patching is advisable.

Affected products

  • Trusted Domain Project OpenDMARC
  • OpenDMARC 1.4.2
  • OpenDMARC 1.4.1
  • OpenDMARC 1.4.0
  • OpenDMARC 1.3.x

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
—
EPSS
—

OpenDMARC PSL Wildcard origin validation email spoofing medium CVE-2026-101278

← All CVEs