CVE-2025-3891

HIGH7.5EPSS 0.67%

libapache2-mod-auth-openidc - security update

Published: 4/29/2025Modified: 7/28/2025
Also known as:GHSA-x7cf-8wgv-5j86BIT-apache-2025-3891

Description

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)