Openspf · Pypolicyd-Spf · CVE-2019-20790
**Name of the Vulnerable Software and Affected Versions**
OpenDMARC versions 1.3.2 and 1.4.x
**Description**
The issue allows attacks to bypass SPF and DMARC authentication when the HELO field is inconsistent with the MAIL FROM field, specifically when OpenDMARC is used with pypolicyd-spf 2.0.2.
**Recommendations**
For OpenDMARC versions 1.3.2 and 1.4.x, consider updating pypolicyd-spf to a version later than 2.0.2 to mitigate the risk of SPF and DMARC authentication bypass.
As a temporary workaround, consider restricting the use of the HELO field to minimize the risk of exploitation.