CVE Vulnerabilities

CVE-2025-3891

Uncaught Exception

Published: Apr 29, 2025 | Modified: Jul 28, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.

Weakness

An exception is thrown from a function, but it is not caught.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache- (including)- (including)
Red Hat Enterprise Linux 8RedHatmod_auth_openidc:2.3-8100020250426100353.489197e6*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatmod_auth_openidc:2.3-8020020250612174445.4cda2c84*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatmod_auth_openidc:2.3-8040020250618101351.522a0ee4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatmod_auth_openidc:2.3-8060020250617090503.ad008a3a*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatmod_auth_openidc:2.3-8060020250617090503.ad008a3a*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatmod_auth_openidc:2.3-8060020250617090503.ad008a3a*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatmod_auth_openidc:2.3-8080020250617090716.63b34585*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatmod_auth_openidc:2.3-8080020250617090716.63b34585*
Red Hat Enterprise Linux 9RedHatmod_auth_openidc-0:2.4.10-1.el9_6.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatmod_auth_openidc-0:2.4.9.4-1.el9_0.3*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatmod_auth_openidc-0:2.4.9.4-1.el9_2.3*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatmod_auth_openidc-0:2.4.9.4-4.el9_4.2*
Libapache2-mod-auth-openidcUbuntufocal*
Libapache2-mod-auth-openidcUbuntuoracular*
Libapache2-mod-auth-openidcUbuntuplucky*

References