[ALSA-2026:79177] Important: mod_auth_openidc security update
Type:
security
Severity:
important
Release date:
2026-10-09
Description:
The mod_auth_openidc is an OpenID Connect authentication module for Apache HTTP Server. It enables an Apache HTTP Server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. Security Fix(es): * mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing (CVE-2026-54789) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
ppc64le mod_auth_openidc-2.4.16.11-1.el9_8.1.ppc64le.rpm f17376a7a28da69b724b3708980963a422d6b3c9c70579f02894f331566a7436
s390x mod_auth_openidc-2.4.16.11-1.el9_8.1.s390x.rpm f6d99198b3ea22b006a81c4685b598a949eecd58a57a103277390e0ffb37d805
x86_64 mod_auth_openidc-2.4.16.11-1.el9_8.1.x86_64.rpm 3311fe98a83d0456b4f03097c4c8d1177886d98f51d23a74e415b3bc93f049fd
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.