rootpwn

high · CVSS v3 7.3

CVE-2026-101281

OpenDMARC versions up to 1.4.2 contain a flaw in the SPF Macro Handler that allows remote attackers to manipulate authentication, potentiall

Overview

OpenDMARC versions up to 1.4.2 contain a flaw in the SPF Macro Handler that allows remote attackers to manipulate authentication, potentially enabling spoofed email delivery. The vulnerability can lead to improper mail-from domain verification. A patch is available to fix the issue.

Description

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue.

Impact

The flaw compromises the integrity of SPF checks, allowing attackers to bypass domain authentication and send spoofed emails. This threatens confidentiality by enabling phishing, integrity by allowing message tampering, and availability if spammers flood the system. Defenders must monitor for anomalous SPF failures and enforce stricter DMARC policies.

Remediation

Apply the official patch identified by commit c48a74c758677fc5272a73eff15ffdbf8afda1a6 to upgrade OpenDMARC to 1.4.3 or later. If patching is not immediately possible, disable the SPF Macro Handler or enforce DMARC reject policies to mitigate spoofing. Verify the installation with 'opendmarc -V' and test SPF validation after update.

Risk context

High severity (CVSS 7.3) and publicly available exploit make this issue urgent. Defenders should prioritize patching within the next 48 hours to mitigate potential spoofing attacks.

Affected products

  • OpenDMARC 1.4.2
  • Trusted Domain Project

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.3
CVSS v4
—
EPSS
—

OpenDMARC SPF Authentication Email HighSeverity Patch DMARC

← All CVEs