mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of mod_auth_openidc. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed Cookie headers (tokens lacking =) can reduce exposure, but upgrading is the recommended remediation.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125",
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54789.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-54789.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"70831870423161090910387495769096353594",
"251522285052450793301443864755380277658",
"177705975256860084344856102528052936787",
"192503434168308454777900497137426301263"
],
"threshold": 0.9
},
"id": "CVE-2026-54789-1f3b0ed8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/8017478471cc071c49aa073c5c9be652a73a8630",
"target": {
"file": "src/state.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "247466007496986471113165742689547077063",
"length": 804
},
"id": "CVE-2026-54789-2b6dcadf",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/8017478471cc071c49aa073c5c9be652a73a8630",
"target": {
"file": "test/test_state.c",
"function": "main"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "193350400988702263902964781649491558353",
"length": 488
},
"id": "CVE-2026-54789-4c62c5e8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/8017478471cc071c49aa073c5c9be652a73a8630",
"target": {
"file": "src/state.c",
"function": "oidc_state_cookies_parse_token"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"299701336619880153036665172526259069740",
"151211151037283842020539100396100715108",
"103069616787231984670234510666743102783",
"218993426657821527075613173926275777958",
"81589264247536892897081541643899056410",
"8709090653557006556792553250146048417",
"196568422358303593685490610712684316383"
],
"threshold": 0.9
},
"id": "CVE-2026-54789-65f39b3b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openidc/mod_auth_openidc/commit/8017478471cc071c49aa073c5c9be652a73a8630",
"target": {
"file": "test/test_state.c"
}
}
]
"2026-09-04T08:11:34Z"