A flaw was found in the mod_auth_openidc module for...
Moderate severity
Unreviewed
Published
Apr 29, 2025
to the GitHub Advisory Database
•
Updated Jul 28, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2025
Published to the GitHub Advisory Database
Apr 29, 2025
Last updated
Jul 28, 2025
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
References