Home

Description

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

PUBLISHED Reserved 2025-04-23 | Published 2025-04-29 | Updated 2025-11-11 | Assigner redhat




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Uncaught Exception

Product status

Default status
unaffected

2.0.0 (semver) before 2.4.13.1
affected

Default status
affected

8100020250426100353.489197e6 (rpm) before *
unaffected

Default status
affected

8020020250612174445.4cda2c84 (rpm) before *
unaffected

Default status
affected

8040020250618101351.522a0ee4 (rpm) before *
unaffected

Default status
affected

8060020250617090503.ad008a3a (rpm) before *
unaffected

Default status
affected

8060020250617090503.ad008a3a (rpm) before *
unaffected

Default status
affected

8060020250617090503.ad008a3a (rpm) before *
unaffected

Default status
affected

8080020250617090716.63b34585 (rpm) before *
unaffected

Default status
affected

8080020250617090716.63b34585 (rpm) before *
unaffected

Default status
affected

0:2.4.10-1.el9_6.2 (rpm) before *
unaffected

Default status
affected

0:2.4.9.4-1.el9_0.3 (rpm) before *
unaffected

Default status
affected

0:2.4.9.4-1.el9_2.3 (rpm) before *
unaffected

Default status
affected

0:2.4.9.4-4.el9_4.2 (rpm) before *
unaffected

Default status
affected

Default status
unaffected

Timeline

2025-04-22:Reported to Red Hat.
2025-04-29:Made public.

References

lists.debian.org/debian-lts-announce/2025/05/msg00007.html

access.redhat.com/errata/RHSA-2025:10002 (RHSA-2025:10002) vendor-advisory

access.redhat.com/errata/RHSA-2025:10003 (RHSA-2025:10003) vendor-advisory

access.redhat.com/errata/RHSA-2025:10004 (RHSA-2025:10004) vendor-advisory

access.redhat.com/errata/RHSA-2025:10006 (RHSA-2025:10006) vendor-advisory

access.redhat.com/errata/RHSA-2025:10007 (RHSA-2025:10007) vendor-advisory

access.redhat.com/errata/RHSA-2025:10008 (RHSA-2025:10008) vendor-advisory

access.redhat.com/errata/RHSA-2025:10010 (RHSA-2025:10010) vendor-advisory

access.redhat.com/errata/RHSA-2025:4597 (RHSA-2025:4597) vendor-advisory

access.redhat.com/errata/RHSA-2025:9396 (RHSA-2025:9396) vendor-advisory

access.redhat.com/security/cve/CVE-2025-3891 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2361633 (RHBZ#2361633) issue-tracking

github.com/...ommit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b

github.com/...penidc/security/advisories/GHSA-x7cf-8wgv-5j86

cve.org (CVE-2025-3891)

nvd.nist.gov (CVE-2025-3891)

Download JSON