CVE-2025-3891
published 2025-04-29CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.32%
68.0th percentile
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libapache2-mod-auth-openidc | < libapache2-mod-auth-openidc 2.4.12.3-2+deb12u4 (bookworm) | libapache2-mod-auth-openidc 2.4.12.3-2+deb12u4 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_auth_openidc: DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled
vendor_redhat·2025-04-29·CVSS 7.5
CVE-2025-3891 [HIGH] CWE-248 mod_auth_openidc: DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled
mod_auth_openidc: DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Package: mod_auth_openidc (Red Hat Enterprise Linux 10) - Fix deferred
Package: mod_auth_openidc (Red Hat Enterprise Linux 7) - Not aff
Debian
CVE-2025-3891: libapache2-mod-auth-openidc - A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allo...
vendor_debian·2025·CVSS 7.5
CVE-2025-3891 [HIGH] CVE-2025-3891: libapache2-mod-auth-openidc - A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allo...
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Scope: local
bookworm: resolved (fixed in 2.4.12.3-2+deb12u4)
bullseye: resolved (fixed in 2.4.9.4-0+deb11u6)
forky: resolved (fixed in 2.4.14.2-1)
sid: resolved (fixed in 2.4.14.2-1)
trixie: resolved (fixed in 2.4.14.2-1)
GHSA
GHSA-v96g-5j57-774c: A flaw was found in the mod_auth_openidc module for Apache httpd
ghsa_unreviewed·2025-04-29
CVE-2025-3891 [MEDIUM] CWE-248 GHSA-v96g-5j57-774c: A flaw was found in the mod_auth_openidc module for Apache httpd
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
OSV
CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd
osv·2025-04-29·CVSS 7.5
CVE-2025-3891 [HIGH] CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2025:10002https://access.redhat.com/errata/RHSA-2025:10003https://access.redhat.com/errata/RHSA-2025:10004https://access.redhat.com/errata/RHSA-2025:10006https://access.redhat.com/errata/RHSA-2025:10007https://access.redhat.com/errata/RHSA-2025:10008https://access.redhat.com/errata/RHSA-2025:10010https://access.redhat.com/errata/RHSA-2025:4597https://access.redhat.com/errata/RHSA-2025:9396https://access.redhat.com/security/cve/CVE-2025-3891https://bugzilla.redhat.com/show_bug.cgi?id=2361633https://github.com/OpenIDC/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2bhttps://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-x7cf-8wgv-5j86https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html
2025-04-29
Published