Back Redpacketsecurity CVE Alert: CVE-2026-100889 – Trusted Domain Project
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early this disclosure but did not respond in any way.
**Risk verdict:** Treat this as an elevated, time-sensitive exposure: a public exploit is reported, but KEV, SSVC and EPSS status are not supplied, so active exploitation and probability cannot be confirmed.
**Why this matters:** A remotely reachable flaw in mail-content processing could affect confidentiality, integrity and availability of the host or mail service. Realistic attacker goals include disrupting mail flow or compromising data handled by the affected process; the available information does not establish reliable code execution.
**Most likely attack path:** The network-reachable, low-complexity path requires no prior privileges or user interaction, so an attacker may be able to trigger it by sending crafted content to a service that processes it. Scope is unchanged, offering no stated basis to assume direct impact on other security domains, although a compromised mail host could provide an operational foothold.
**Who is most exposed:** Internet-facing mail gateways and servers that perform message signing or verification are the key deployment patterns to review. Risk depends on whether the vulnerable decoding path is enabled and processes untrusted messages.
Review mail-service crashes, restarts and unusual resource use after malformed-message handling.
logs for repeated delivery attempts from the same sources with abnormal encoded content.
Check process and host telemetry for unexpected child processes or outbound connections.
Identify deployed builds and whether the decoder is invoked on inbound traffic.
Mitigation and prioritisation
Confirm whether a vendor fix or validated safe build is available; upgrade promptly and test mail handling.
Until then, restrict exposure to trusted mail paths and apply gateway filtering for suspicious content.
Monitor service health and preserve relevant logs; avoid disabling mail controls without a tested alternative.
Check KEV, SSVC and EPSS feeds before setting final priority; their absence here leaves urgency uncertain.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
