CVE-2026-54789
Description
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of mod_auth_openidc. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed Cookie headers (tokens lacking =) can reduce exposure, but upgrading is the recommended remediation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/apache2-mod_auth_openidc&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/apache2-mod_auth_openidc&distro=openSUSE%20Leap%2016.0
< 2.4.20.2-1.1+ 1 more
- (no CPE)range: < 2.4.20.2-1.1
- (no CPE)range: < 2.4.17.1-160000.2.1
- Range: <2.4.19.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.