Description:
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.
Security Fix(es):
* mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing (CVE-2026-54789)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
mod_auth_openidc-2.4.16.11-1.el10_2.1.aarch64.rpm |
c11e84983fb23d89d1544ea53509d81da32d91257e8d9380f0f2a945c02f5b3c |
| ppc64le |
mod_auth_openidc-2.4.16.11-1.el10_2.1.ppc64le.rpm |
18d554a08e61228dc2de4e54486e86d476b049b5d24ddcb63f0f5c9cbbede8fd |
| s390x |
mod_auth_openidc-2.4.16.11-1.el10_2.1.s390x.rpm |
754f969fd2bf048d0e46042f7964c92d458bc1a3c8c0c3e66c400539c828bd2c |
| x86_64 |
mod_auth_openidc-2.4.16.11-1.el10_2.1.x86_64.rpm |
79c04f6326c5e6c332b4c40962009cf20a1c8590e1c3634776615844cdc28d8a |
| x86_64_v2 |
mod_auth_openidc-2.4.16.11-1.el10_2.1.x86_64_v2.rpm |
2d2bb5a5e3c1c3911bdb59794041d1faadb5dbac0aca576651e7f1f592815b79 |