Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-54789] Denial of Service via malformed state cookie parsing

This high-severity Red Hat Linux advisory covers CVE-2026-54789 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-54789 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`.

The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available.

As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie.

This is an Important denial of service flaw in `mod_auth_openidc`. Exploitation could lead to service unavailability for systems configured with `mod_auth_openidc` for OpenID Connect Relying Party functionality.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125.

Affected versions
  • < 2.4.19.4

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Fixed versions
  • 2.4.19.4
  • mod_auth_openidc-0:2.4.15-4.el10_0.2
  • mod_auth_openidc-0:1.8.8-9.el7_9.2
  • mod_auth_openidc:2.3-8040020260911120429.522a0ee4
  • mod_auth_openidc:2.3-8060020260911120020.ad008a3a
  • mod_auth_openidc:2.3-8080020260916055033.63b34585
  • mod_auth_openidc-0:2.4.9.4-1.el9_2.4
  • mod_auth_openidc-0:2.4.9.4-4.el9_4.3
  • mod_auth_openidc-0:2.4.10-1.el9_6.3
  • RHSA-2026:69719
  • RHSA-2026:69715
  • RHSA-2026:69712
  • RHSA-2026:69713
  • RHSA-2026:69717
  • RHSA-2026:69720
  • RHSA-2026:69718
  • RHSA-2026:69716

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Inspect incoming HTTP requests using a Web Application Firewall (WAF), reverse proxy, or Apache’s mod_rewrite module prior to evaluation by mod_auth_openidc. Configure security rules to reject or drop any requests containing malformed Cookie headers—specifically OpenID Connect state cookie tokens that lack an equals sign (=).

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.