Back Redpacketsecurity CVE Alert: CVE-2026-100888 – Trusted Domain Project
A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early this disclosure but did not respond in any way.
**Risk verdict:** This warrants prompt investigation and remediation: public exploit material is reported, but KEV status, SSVC exploitation state and EPSS are not supplied, so active exploitation and priority classification remain uncertain.
**Why this matters:** A successful memory-corruption attack could affect the mail-processing service’s confidentiality, integrity or availability, potentially disrupting mail flow or compromising the service process. Because the vulnerable code handles DKIM header selection, attacker-crafted messages are a plausible delivery vehicle; the extent of compromise is not established by the available data.
**Most likely attack path:** An unauthenticated remote attacker sends a crafted message to a system that processes it through the affected DKIM functionality; no user interaction or special conditions are indicated. The stated unchanged scope suggests impact is initially confined to the vulnerable service, although access to its privileges or host could create further risk.
**Who is most exposed:** Internet-facing mail gateways and organisations running DKIM signing or verification within inbound or outbound mail pipelines are most exposed, especially where message processing is directly reachable.
Review mail logs for malformed or unusually large DKIM-related headers and repeated processing failures.
Alert on unexpected crashes, restarts or memory faults in mail-filtering processes.
Check for suspicious child processes, outbound connections or file changes from mail-service accounts.
Mitigation and prioritisation
Identify deployments and obtain vendor or maintainer guidance; apply a verified fixed release when available.
Until then, restrict access to mail-processing interfaces and isolate the service with least privilege.
Consider disabling the affected processing path only after assessing mail-flow and signing impact.
Preserve logs and crash artefacts; use staged change control and validate mail delivery after remediation.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
