A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...
zetlyn/cve-ghsa vulnerability ghsa GHSA-87hw-mmxf-r6m3 cve CVE-2026-100889 known 2026-09-28
https://github.com/advisories/GHSA-87hw-mmxf-r6m3
Properties
| cvss | 7.3receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100889",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [],
"description": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"epss": {
"percentage": 0.003,
"percentile": 0.20331
},
"ghsa_id": "GHSA-87hw-mmxf-r6m3",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-87hw-mmxf-r6m3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-87hw-mmxf-r6m3"
},
{
"type": "CVE",
"value": "CVE-2026-100889"
}
],
"nvd_published_at": "2026-09-28T00:16:32Z",
"published_at": "2026-09-28T00:30:28Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100889",
"https://vuldb.com/cve/CVE-2026-100889",
"https://vuldb.com/submit/917063",
"https://vuldb.com/vuln/410839",
"https://vuldb.com/vuln/410839/cti",
"https://weitongli.com/share/opendkim-qp-off-by-one.html",
"https://github.com/advisories/GHSA-87hw-mmxf-r6m3"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...",
"type": "unreviewed",
"updated_at": "2026-09-28T00:30:36Z",
"url": "https://api.github.com/advisories/GHSA-87hw-mmxf-r6m3",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| severity | mediumreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100889",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [],
"description": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"epss": {
"percentage": 0.003,
"percentile": 0.20331
},
"ghsa_id": "GHSA-87hw-mmxf-r6m3",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-87hw-mmxf-r6m3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-87hw-mmxf-r6m3"
},
{
"type": "CVE",
"value": "CVE-2026-100889"
}
],
"nvd_published_at": "2026-09-28T00:16:32Z",
"published_at": "2026-09-28T00:30:28Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100889",
"https://vuldb.com/cve/CVE-2026-100889",
"https://vuldb.com/submit/917063",
"https://vuldb.com/vuln/410839",
"https://vuldb.com/vuln/410839/cti",
"https://weitongli.com/share/opendkim-qp-off-by-one.html",
"https://github.com/advisories/GHSA-87hw-mmxf-r6m3"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...",
"type": "unreviewed",
"updated_at": "2026-09-28T00:30:36Z",
"url": "https://api.github.com/advisories/GHSA-87hw-mmxf-r6m3",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.