A flaw was found in the modauthopenidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
[
{
"id": "CVE-2025-3891-0cdcbe7c",
"source": "https://github.com/openidc/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b",
"digest": {
"length": 663.0,
"function_hash": "211198591416651378099077896614660068044"
},
"target": {
"file": "src/mod_auth_openidc.c",
"function": "oidc_original_request_method"
},
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1"
},
{
"id": "CVE-2025-3891-4b8990d0",
"source": "https://github.com/openidc/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b",
"digest": {
"line_hashes": [
"239289886643070125605459760189440756043",
"229876794043611023403253123313672969009",
"263559125609405718920736118279668036461",
"44104131586549595805645968922353939301"
],
"threshold": 0.9
},
"target": {
"file": "src/mod_auth_openidc.c"
},
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1"
}
]