A flaw was found in the modauthopenidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
{ "vanir_signatures": [ { "id": "CVE-2025-3891-0cdcbe7c", "digest": { "length": 663.0, "function_hash": "211198591416651378099077896614660068044" }, "signature_version": "v1", "target": { "file": "src/mod_auth_openidc.c", "function": "oidc_original_request_method" }, "deprecated": false, "signature_type": "Function", "source": "https://github.com/openidc/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b" }, { "id": "CVE-2025-3891-4b8990d0", "digest": { "threshold": 0.9, "line_hashes": [ "239289886643070125605459760189440756043", "229876794043611023403253123313672969009", "263559125609405718920736118279668036461", "44104131586549595805645968922353939301" ] }, "signature_version": "v1", "target": { "file": "src/mod_auth_openidc.c" }, "deprecated": false, "signature_type": "Line", "source": "https://github.com/openidc/mod_auth_openidc/commit/6a0b5f66c87184dfe0e4400f6bdd46a82dc0ec2b" } ] }