Finding #174 — CVE-2025-3891
| Inventory item | apache-test2 2.4.37 (software, apache) |
|---|---|
| Title | CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending |
| Match | cpe / confidence medium |
| Status | new |
| First seen | 2026-06-25T06:50:23Z |
| Last updated | 2026-06-25T06:50:23Z |
| CVE | CVE-2025-3891 |
| CVSS | 7.5 (HIGH)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Description | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability. |
| Source advisory | CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability. |
| References | https://access.redhat.com/errata/RHSA-2025:10002 https://access.redhat.com/errata/RHSA-2025:10003 https://access.redhat.com/errata/RHSA-2025:10004 https://access.redhat.com/errata/RHSA-2025:10006 https://access.redhat.com/errata/RHSA-2025:10007 https://access.redhat.com/errata/RHSA-2025:10008 https://access.redhat.com/errata/RHSA-2025:10010 https://access.redhat.com/errata/RHSA-2025:4597 https://access.redhat.com/errata/RHSA-2025:9396 https://access.redhat.com/security/cve/CVE-2025-3891 https://bugzilla.redhat.com/show_bug.cgi?id=2361633 https://github.com/OpenIDC/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-x7cf-8wgv-5j86 https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html |