A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094a27c71e7369bdedc62ae. To fix this issue, it is recommended to deploy a patch.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-101014 is a high-severity off-by-one vulnerability in OpenDMARC's email authentication parser, specifically within the opendmarc_util_cleanup function. This memory safety flaw affects versions up to 1.4.2 and allows remote attackers to manipulate DMARC record processing, potentially leading to memory corruption, information disclosure, or denial of service. Organizations deploying OpenDMARC for DMARC policy validation—a critical email security control—face exposure to unauthenticated attacks since DMARC processing occurs during normal mail receipt. This vulnerability is particularly concerning because DMARC infrastructure is foundational to email authentication pipelines used across government, finance, and enterprise sectors.
While this specific vulnerability does not directly map to MITRE ATT&CK techniques in the CVE record, Casky's skills would help practitioners detect exploitation attempts by identifying anomalous patterns in email authentication failures, unexpected memory faults in mail processing logs, and suspicious DMARC record formats that could trigger the parser's off-by-one condition. Practitioners using Casky would examine Defense Evasion (T1566 - Phishing) and Initial Access attack chains, as successful exploitation could lead to authentication bypass or mail delivery manipulation. Extended reasoning capabilities would correlate unexpected system crashes or memory errors in opendmarc processes with malformed email headers or DMARC records, enabling earlier detection of active exploitation attempts before widespread impact occurs. Immediate patching to commit b3b1da9264bc80324094a27c71e7369bdedc62ae is critical.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-101014. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation