[ALSA-2026:75581] Important: mod_auth_openidc security update
Type:
security
Severity:
important
Release date:
2026-10-06
Description:
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. Security Fix(es): * mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing (CVE-2026-54789) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 mod_auth_openidc-2.4.16.11-1.el10_2.1.aarch64.rpm c11e84983fb23d89d1544ea53509d81da32d91257e8d9380f0f2a945c02f5b3c
ppc64le mod_auth_openidc-2.4.16.11-1.el10_2.1.ppc64le.rpm 18d554a08e61228dc2de4e54486e86d476b049b5d24ddcb63f0f5c9cbbede8fd
s390x mod_auth_openidc-2.4.16.11-1.el10_2.1.s390x.rpm 754f969fd2bf048d0e46042f7964c92d458bc1a3c8c0c3e66c400539c828bd2c
x86_64 mod_auth_openidc-2.4.16.11-1.el10_2.1.x86_64.rpm 79c04f6326c5e6c332b4c40962009cf20a1c8590e1c3634776615844cdc28d8a
x86_64_v2 mod_auth_openidc-2.4.16.11-1.el10_2.1.x86_64_v2.rpm 2d2bb5a5e3c1c3911bdb59794041d1faadb5dbac0aca576651e7f1f592815b79
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.