A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
libapache2-mod-auth-openidc Debian
cjose Red Hat / RHEL
Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.src::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.src::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.src::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.src::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.src::mod_auth_openidc:2.3 RHSA-2025:10003 cjose Rocky
Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.src::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.src::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.src::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.src::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.src::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 cjose-debuginfo Red Hat / RHEL
Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 cjose-debuginfo Rocky
Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 cjose-debugsource Rocky
Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 cjose-debugsource Red Hat / RHEL
Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 cjose-devel Red Hat / RHEL
Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 cjose-devel Rocky
Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.s390x::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-3.module+el8.2.0+19461+3a40b6ee.x86_64::mod_auth_openidc:2.3 RHSA-2025:10006 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.x86_64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.aarch64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.aarch64::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.ppc64le::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-3.module+el8.8.0+19464+578f4546.x86_64::mod_auth_openidc:2.3 RHSA-2025:10010 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.s390x::mod_auth_openidc:2.3 RHSA-2025:4597 Fixed in: 0:0.6.1-3.module+el8.4.0+19462+14bde120.x86_64::mod_auth_openidc:2.3 RHSA-2025:10004 Fixed in: 0:0.6.1-3.module+el8.6.0+19463+7d2e1f9c.x86_64::mod_auth_openidc:2.3 RHSA-2025:10003 Fixed in: 0:0.6.1-4.module+el8.10.0+21813+b5444eb8.ppc64le::mod_auth_openidc:2.3 RHSA-2025:4597 mod_auth_openidc Red Hat / RHEL
mod_auth_openidc-debuginfo Red Hat / RHEL
mod_auth_openidc-debuginfo Rocky
mod_auth_openidc-debugsource Rocky
mod_auth_openidc-debugsource Red Hat / RHEL
TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality None
Integrity None
Availability High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1.32% probability of exploitation in 30 days
68th percentile
Moderate risk: more likely to be exploited than 68% of all known CVEs.
Other CWE-248 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2025-3891 Markdown
[](https://tridentstack.com/cve/CVE-2025-3891)HTML
<a href="https://tridentstack.com/cve/CVE-2025-3891"><img src="https://tridentstack.com/cve/badge/CVE-2025-3891.svg" alt="CVE-2025-3891"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-06-29.