CVE-2025-3891
29.04.2025, 12:15
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | - |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration