CVE-2025-3891

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 29, 2025
Updated: May 12, 2025
CWE ID 248

Summary

CVE-2025-3891 is a recently identified vulnerability affecting the mod_auth_openidc module used in Apache httpd. This issue permits an unauthenticated remote attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently as a result, leading to a significant impact on availability. This vulnerability underscores the importance of securing web applications and ensuring that all modules and components are up to date with the latest security patches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux
  • Debian

Affected Vendors

  • Red Hat
  • Debian