CVE-2025-3891
Red Hat Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
- CVSS
- 7.5
- EPSS
- 1.42% 70.3% percentile
- CISA KEV
- Not listed
- Published
- 2025.04.29