CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

12 May 2025, 19:36

Type Values Removed Values Added
First Time Debian
Redhat enterprise Linux
Redhat
Debian debian Linux
Apache http Server
Apache
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2025:4597 - () https://access.redhat.com/errata/RHSA-2025:4597 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2025-3891 - () https://access.redhat.com/security/cve/CVE-2025-3891 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2361633 - () https://bugzilla.redhat.com/show_bug.cgi?id=2361633 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html - () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html - Mailing List, Third Party Advisory

08 May 2025, 11:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html -

07 May 2025, 03:15

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en el módulo mod_auth_openidc para Apache httpd. Esta falla permite que un atacante remoto no autenticado active una denegación de servicio enviando una solicitud POST vacía cuando la directiva OIDCPreservePost está habilitada. El servidor se bloquea constantemente, lo que afecta la disponibilidad.
References
  • () https://access.redhat.com/errata/RHSA-2025:4597 -

29 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 12:15

Updated : 2025-05-12 19:36


NVD link : CVE-2025-3891

Mitre link : CVE-2025-3891

CVE.ORG link : CVE-2025-3891


JSON object : View

Products Affected

debian

  • debian_linux

apache

  • http_server

redhat

  • enterprise_linux
CWE
CWE-248

Uncaught Exception

NVD-CWE-noinfo