Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54789

Опубликовано: 21 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of mod_auth_openidc. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed Cookie headers (tokens lacking =) can reduce exposure, but upgrading is the recommended remediation.

A flaw was found in mod_auth_openidc, an OpenID Connect Relying Party module for Apache HTTP servers. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie. This can lead to an out-of-bounds read and a one-byte out-of-bounds write during state cookie parsing, primarily resulting in a Denial of Service (DoS) for the affected server.

Отчет

This is an Important denial of service flaw in mod_auth_openidc. The vulnerability arises from an out-of-bounds read and write in the state-cookie parser when processing specially crafted Cookie headers. Exploitation could lead to service unavailability for systems configured with mod_auth_openidc for OpenID Connect Relying Party functionality.

Меры по смягчению последствий

Inspect incoming HTTP requests using a Web Application Firewall (WAF), reverse proxy, or Apache’s mod_rewrite module prior to evaluation by mod_auth_openidc. Configure security rules to reject or drop any requests containing malformed Cookie headers—specifically OpenID Connect state cookie tokens that lack an equals sign (=).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mod_auth_openidcAffected
Red Hat Enterprise Linux 7mod_auth_openidcAffected
Red Hat Enterprise Linux 8mod_auth_openidc:2.3/mod_auth_openidcAffected
Red Hat Enterprise Linux 9mod_auth_openidcAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2521051mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing

EPSS

Процентиль: 40%
0.00488
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
15 дней назад

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.

CVSS3: 7.5
nvd
15 дней назад

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.

CVSS3: 7.5
debian
15 дней назад

mod_auth_openidc is an OpenID Certified authentication and authorizati ...

suse-cvrf
5 дней назад

Security update for apache2-mod_auth_openidc

EPSS

Процентиль: 40%
0.00488
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-54789