CVE-2025-3891

Publication date

2025-04-29 11:56:50

Family

redhat

State

PUBLISHED

Description

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.