medium · CVSS v3 6.5
CVE-2026-101279
OpenDMARC up to 1.4.2 contains an integer overflow in the pct argument of the DMARC parser, which can be triggered remotely and may corrupt
Overview
OpenDMARC up to 1.4.2 contains an integer overflow in the pct argument of the DMARC parser, which can be triggered remotely and may corrupt memory or cause a denial of service. It affects any mail server using the vulnerable OpenDMARC library.
Description
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The integer overflow can lead to memory corruption, potentially allowing attackers to crash the DMARC parser or execute arbitrary code, compromising the confidentiality, integrity, and availability of mail processing. Mail administrators and email service providers are the primary defenders impacted.
Remediation
Check the OpenDMARC version on all mail servers. Upgrade to version 1.4.3 or later where the pct handling is fixed. If an upgrade is not immediately possible, disable or sanitize the pct tag in incoming DMARC records, or apply a local patch that bounds the pct value to 0–100. Monitor logs for parsing errors or crashes.
Risk context
Severity is medium (CVSS 6.5). No EPSS data is available. The vulnerability is publicly disclosed and exploitable, so timely patching is recommended.
Affected products
- Trusted Domain Project OpenDMARC
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —