Out-of-Bounds Read and Write Vulnerability in Apache mod_auth_openidc
CVE-2026-54789

7.5HIGH

Key Information:

Vendor

Openidc

Vendor
CVE Published:
21 August 2026

What is CVE-2026-54789?

The mod_auth_openidc plugin for Apache is vulnerable to an out-of-bounds read and write due to improper handling of cookie state while parsing state-cookies. Prior to version 2.4.19.4, this vulnerability allows attackers to manipulate the state-cookie input, potentially leading to unauthorized access or system instability. The issue has been remedied in the latest version, which stops the scan at the string terminator, preventing the processing of value-less tokens. While upgrading is essential for proper remediation, organizations are advised to consider employing a reverse proxy or WAF that can filter malformed Cookie headers as a temporary measure.

Affected Version(s)

mod_auth_openidc < 2.4.19.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.