A flaw was found in the modauthopenidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3891.json",
"cwe_ids": [
"CWE-248"
],
"cna_assigner": "redhat"
}[
{
"digest": {
"line_hashes": [
"64978875816620747788720445007160513623",
"271594790058963848889881620267568419497",
"192082871201767715712966956076527375237",
"186523850938774963886596464906350199293"
],
"threshold": 0.9
},
"id": "CVE-2025-3891-8d12588a",
"signature_version": "v1",
"target": {
"file": "src/jose.c"
},
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/openidc/mod_auth_openidc/commit/5050a96dca441a921c95521bff6e47caa40c750b"
},
{
"digest": {
"function_hash": "146796389184166318347761834619920743023",
"length": 407.0
},
"id": "CVE-2025-3891-cdcc88f6",
"signature_version": "v1",
"target": {
"file": "src/jose.c",
"function": "oidc_jwk_list_copy"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/openidc/mod_auth_openidc/commit/5050a96dca441a921c95521bff6e47caa40c750b"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-3891.json"
"2026-05-31T02:47:18Z"