CVE-2025-3891 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending…
High CVSS: 7.5

CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
Vendor
Apache
Product
Http Server
CWE
CWE-248
Yayın Tarihi
2025-04-29 12:15:32
Güncelleme
2025-07-28 14:15:27
Source Identifier
secalert@redhat.com
KEV Date Added
-

Kategoriler

Referanslar