CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

12 May 2025, 19:36

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2025:4597 - () https://access.redhat.com/errata/RHSA-2025:4597 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2025-3891 - () https://access.redhat.com/security/cve/CVE-2025-3891 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2361633 - () https://bugzilla.redhat.com/show_bug.cgi?id=2361633 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html - () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html - Mailing List, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:apache:http_server:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
First Time Apache http Server
Redhat
Debian debian Linux
Apache
Debian
Redhat enterprise Linux

08 May 2025, 11:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html -

07 May 2025, 03:15

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en el módulo mod_auth_openidc para Apache httpd. Esta falla permite que un atacante remoto no autenticado active una denegación de servicio enviando una solicitud POST vacía cuando la directiva OIDCPreservePost está habilitada. El servidor se bloquea constantemente, lo que afecta la disponibilidad.
References
  • () https://access.redhat.com/errata/RHSA-2025:4597 -

29 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 12:15

Updated : 2025-05-12 19:36


NVD link : CVE-2025-3891

Mitre link : CVE-2025-3891

CVE.ORG link : CVE-2025-3891


JSON object : View

Products Affected

redhat

  • enterprise_linux

debian

  • debian_linux

apache

  • http_server
CWE
CWE-248

Uncaught Exception

NVD-CWE-noinfo