A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
https://lists.debian.org/debian-lts-announce/2025/05/msg00007.html
https://access.redhat.com/security/cve/CVE-2025-3891
https://access.redhat.com/errata/RHSA-2025:9396
https://access.redhat.com/errata/RHSA-2025:4597
https://access.redhat.com/errata/RHSA-2025:10010
https://access.redhat.com/errata/RHSA-2025:10008
https://access.redhat.com/errata/RHSA-2025:10007
https://access.redhat.com/errata/RHSA-2025:10006
https://access.redhat.com/errata/RHSA-2025:10004