CVE-2026-54789
CVE-2026-54789: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-54789] Denial of Service via malformed state cookie parsing
CVE-2026-54789Source published Source updated
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie. This is an…
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
8 more entries in the full advisory.
- Source-reported affected versions
- < 2.4.19.4
- Source-reported fixed versions
- 2.4.19.4
- mod_auth_openidc-0:2.4.15-4.el10_0.2
- mod_auth_openidc-0:1.8.8-9.el7_9.2
- mod_auth_openidc:2.3-8040020260911120429.522a0ee4
13 more entries in the full advisory.
- Mitigation guidance
- Inspect incoming HTTP requests using a Web Application Firewall (WAF), reverse proxy, or Apache’s mod_rewrite module prior to evaluation by mod_auth_openidc. Configure security rules to reject or drop any requests containing malformed Cookie headers—specifically OpenID Connect state cookie tokens that lack an equals sign (=).
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.