CVE-2026-100889 Details
Description
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Trusted Domain Project OpenDKIM versions through 2.11.0, specifically in the Decoder component's dkim_qp_decode function within util.c. This off-by-one vulnerability can be exploited remotely, leading to an out-of-bounds read of stack memory. The issue arises when a DKIM-Signature header's 'i=' tag is long enough to overwrite the buffer's null terminator, causing a crash in the verification process or, under normal conditions, an undefined behavior information-disclosure oracle.
The vulnerability has been fixed in the latest version of OpenDKIM. Users should update to this version. The fix involved changing the bounds check in the dkim_qp_decode function from inclusive to exclusive, ensuring that the null terminator is not overwritten.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-100889 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/917063 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410839 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/410839/cti | [email protected] | Content Wall |
| https://weitongli.com/share/opendkim-qp-off-by-one.html | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-193 | Off-by-one Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Trusted Domain Project OpenDKIM | <= 2.11.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion