Security Advisory

CVE-2025-3891

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-29 11:56:50
Last updated 2025-11-11 12:09:56
Assigner redhat
State PUBLISHED

Description

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.