A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...

zetlyn/cve-ghsa vulnerability ghsa GHSA-87hw-mmxf-r6m3 cve CVE-2026-100889 known 2026-09-28

https://github.com/advisories/GHSA-87hw-mmxf-r6m3

Properties

cvss7.3
receipt
Source
GitHub advisories
Its words
7.3
Read by
field:cvss.score
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-100889",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 5.5,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [],
  "description": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
  "epss": {
    "percentage": 0.003,
    "percentile": 0.20331
  },
  "ghsa_id": "GHSA-87hw-mmxf-r6m3",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-87hw-mmxf-r6m3",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-87hw-mmxf-r6m3"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-100889"
    }
  ],
  "nvd_published_at": "2026-09-28T00:16:32Z",
  "published_at": "2026-09-28T00:30:28Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-100889",
    "https://vuldb.com/cve/CVE-2026-100889",
    "https://vuldb.com/submit/917063",
    "https://vuldb.com/vuln/410839",
    "https://vuldb.com/vuln/410839/cti",
    "https://weitongli.com/share/opendkim-qp-off-by-one.html",
    "https://github.com/advisories/GHSA-87hw-mmxf-r6m3"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...",
  "type": "unreviewed",
  "updated_at": "2026-09-28T00:30:36Z",
  "url": "https://api.github.com/advisories/GHSA-87hw-mmxf-r6m3",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-100889",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 5.5,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [],
  "description": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
  "epss": {
    "percentage": 0.003,
    "percentile": 0.20331
  },
  "ghsa_id": "GHSA-87hw-mmxf-r6m3",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-87hw-mmxf-r6m3",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-87hw-mmxf-r6m3"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-100889"
    }
  ],
  "nvd_published_at": "2026-09-28T00:16:32Z",
  "published_at": "2026-09-28T00:30:28Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-100889",
    "https://vuldb.com/cve/CVE-2026-100889",
    "https://vuldb.com/submit/917063",
    "https://vuldb.com/vuln/410839",
    "https://vuldb.com/vuln/410839/cti",
    "https://weitongli.com/share/opendkim-qp-off-by-one.html",
    "https://github.com/advisories/GHSA-87hw-mmxf-r6m3"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the...",
  "type": "unreviewed",
  "updated_at": "2026-09-28T00:30:36Z",
  "url": "https://api.github.com/advisories/GHSA-87hw-mmxf-r6m3",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the... A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.