High [CVE-2026-54789] Denial of Service via malformed state cookie parsing
This high-severity Red Hat Linux advisory covers CVE-2026-54789 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`.
The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available.
As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie.
This is an Important denial of service flaw in `mod_auth_openidc`. Exploitation could lead to service unavailability for systems configured with `mod_auth_openidc` for OpenID Connect Relying Party functionality.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125.
- < 2.4.19.4
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
- 2.4.19.4
- mod_auth_openidc-0:2.4.15-4.el10_0.2
- mod_auth_openidc-0:1.8.8-9.el7_9.2
- mod_auth_openidc:2.3-8040020260911120429.522a0ee4
- mod_auth_openidc:2.3-8060020260911120020.ad008a3a
- mod_auth_openidc:2.3-8080020260916055033.63b34585
- mod_auth_openidc-0:2.4.9.4-1.el9_2.4
- mod_auth_openidc-0:2.4.9.4-4.el9_4.3
- mod_auth_openidc-0:2.4.10-1.el9_6.3
- RHSA-2026:69719
- RHSA-2026:69715
- RHSA-2026:69712
- RHSA-2026:69713
- RHSA-2026:69717
- RHSA-2026:69720
- RHSA-2026:69718
- RHSA-2026:69716
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Inspect incoming HTTP requests using a Web Application Firewall (WAF), reverse proxy, or Apache’s mod_rewrite module prior to evaluation by mod_auth_openidc. Configure security rules to reject or drop any requests containing malformed Cookie headers—specifically OpenID Connect state cookie tokens that lack an equals sign (=).
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.