Trusteddomain maintains OpenDMARC, a narrowly scoped but strategically positioned email authentication implementation widely embedded in mail-server deployments and security appliances. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and concentrate in authentication-bypass and memory-safety weakness classes—spoofing vulnerabilities in DMARC validation logic and NULL-pointer dereferences and out-of-bounds writes characteristic of C-based protocol parsers—reflecting the authentication-critical and low-level nature of the codebase. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trusteddomain over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20790CRITICAL OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent wi | Apr 27, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-16378CRITICAL OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a do | Sep 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2020-12460CRITICAL OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml | Jul 27, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-34555HIGH OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field. | Jun 10, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-25768HIGH OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c. | Feb 26, 2024 | 7.5 | 19 | NO | NO |
CVE-2020-12272MEDIUM OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused | Apr 27, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trusteddomain.
Media articles that mention a CVE ID that affects a product developed by Trusteddomain — matched by CVE ID, not by vendor name.