Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-54789

CVE-2026-54789: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-54789] Denial of Service via malformed state cookie parsing

    CVE-2026-54789Source published Source updated

    mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie. This is an…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10.0 Extended Update Support
    • Red Hat Enterprise Linux 7 Extended Lifecycle Support
    • Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
    • Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

    8 more entries in the full advisory.

    Source-reported affected versions
    • < 2.4.19.4
    Source-reported fixed versions
    • 2.4.19.4
    • mod_auth_openidc-0:2.4.15-4.el10_0.2
    • mod_auth_openidc-0:1.8.8-9.el7_9.2
    • mod_auth_openidc:2.3-8040020260911120429.522a0ee4

    13 more entries in the full advisory.

    Mitigation guidance
    • Inspect incoming HTTP requests using a Web Application Firewall (WAF), reverse proxy, or Apache’s mod_rewrite module prior to evaluation by mod_auth_openidc. Configure security rules to reject or drop any requests containing malformed Cookie headers—specifically OpenID Connect state cookie tokens that lack an equals sign (=).

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery