Description:
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.
Security Fix(es):
* mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing (CVE-2026-54789)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| ppc64le |
mod_auth_openidc-2.4.16.11-1.el9_8.1.ppc64le.rpm |
f17376a7a28da69b724b3708980963a422d6b3c9c70579f02894f331566a7436 |
| s390x |
mod_auth_openidc-2.4.16.11-1.el9_8.1.s390x.rpm |
f6d99198b3ea22b006a81c4685b598a949eecd58a57a103277390e0ffb37d805 |
| x86_64 |
mod_auth_openidc-2.4.16.11-1.el9_8.1.x86_64.rpm |
3311fe98a83d0456b4f03097c4c8d1177886d98f51d23a74e415b3bc93f049fd |