Out-of-Bounds Read and Write Vulnerability in Apache mod_auth_openidc
CVE-2026-54789
7.5HIGH
What is CVE-2026-54789?
The mod_auth_openidc plugin for Apache is vulnerable to an out-of-bounds read and write due to improper handling of cookie state while parsing state-cookies. Prior to version 2.4.19.4, this vulnerability allows attackers to manipulate the state-cookie input, potentially leading to unauthorized access or system instability. The issue has been remedied in the latest version, which stops the scan at the string terminator, preventing the processing of value-less tokens. While upgrading is essential for proper remediation, organizations are advised to consider employing a reverse proxy or WAF that can filter malformed Cookie headers as a temporary measure.
Affected Version(s)
mod_auth_openidc < 2.4.19.4
