A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
An exception is thrown from a function, but it is not caught.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2025:10002 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10003 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10004 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10006 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10007 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10008 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:10010 | vendor advisory |
https://access.redhat.com/errata/RHSA-2025:4597 | vendor advisory third party advisory |
https://access.redhat.com/errata/RHSA-2025:9396 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2025-3891 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2361633 | issue tracking |
https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html | mailing list third party advisory |