CVE-2026-100889: Off-by-One in Trusted Domain Project OpenDKIM
CVE-2026-100889 is an off-by-one vulnerability in the dkim_qp_decode function of the util.c file in Trusted Domain Project OpenDKIM up to version 2.11.0. This flaw allows remote attackers to manipulate the decoding process, potentially leading to memory corruption or related issues. The vulnerability has a medium severity rating with a CVSS score of 6.9. Public exploit code is available, but there is no vendor response or patch provided at this time.
AI Analysis
Technical Summary
An off-by-one error exists in the dkim_qp_decode function within the util.c component of Trusted Domain Project OpenDKIM versions up to 2.11.0. This vulnerability can be triggered remotely and may result in memory corruption or similar unintended behavior. The vulnerability is publicly disclosed with exploit code available, but the vendor has not issued any response or fix.
Potential Impact
The off-by-one vulnerability can be exploited remotely without authentication, potentially leading to partial memory corruption or other unintended side effects. The CVSS 4.0 vector indicates low complexity and no privileges or user interaction required, with partial impact on confidentiality, integrity, and availability. However, no confirmed exploitation in the wild has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or released a fix, users should monitor official Trusted Domain Project communications for updates. Until a patch is available, consider mitigating exposure by restricting access to OpenDKIM services and applying general best practices for limiting remote attack surfaces.
CVE-2026-100889: Off-by-One in Trusted Domain Project OpenDKIM
Description
CVE-2026-100889 is an off-by-one vulnerability in the dkim_qp_decode function of the util.c file in Trusted Domain Project OpenDKIM up to version 2.11.0. This flaw allows remote attackers to manipulate the decoding process, potentially leading to memory corruption or related issues. The vulnerability has a medium severity rating with a CVSS score of 6.9. Public exploit code is available, but there is no vendor response or patch provided at this time.
CVSS v4.0
Score 6.9medium
Affected software
Trusted Domain Project
OpenDKIM
pkg:deb/trusted_domain_project/opendkimcpe:2.3:a:trusted_domain_project:opendkim:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An off-by-one error exists in the dkim_qp_decode function within the util.c component of Trusted Domain Project OpenDKIM versions up to 2.11.0. This vulnerability can be triggered remotely and may result in memory corruption or similar unintended behavior. The vulnerability is publicly disclosed with exploit code available, but the vendor has not issued any response or fix.
Potential Impact
The off-by-one vulnerability can be exploited remotely without authentication, potentially leading to partial memory corruption or other unintended side effects. The CVSS 4.0 vector indicates low complexity and no privileges or user interaction required, with partial impact on confidentiality, integrity, and availability. However, no confirmed exploitation in the wild has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded or released a fix, users should monitor official Trusted Domain Project communications for updates. Until a patch is available, consider mitigating exposure by restricting access to OpenDKIM services and applying general best practices for limiting remote attack surfaces.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-27T07:35:55.983Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab9ab47f7a7c54106a21235
Added to database: 09/27/2026, 23:48:23 UTC
Last enriched: 09/28/2026, 00:02:41 UTC
Last updated: 09/28/2026, 00:16:10 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.