Debian Package Tracker
Register | Log in
Subscribe

libapache2-mod-auth-openidc

OpenID Connect Relying Party implementation for Apache

Choose email to subscribe with

general
  • source: libapache2-mod-auth-openidc (main)
  • version: 2.4.20.2-1
  • maintainer: Moritz Schlarb (DMD)
  • uploaders: Christoph Martin [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.4.9.4-0+deb11u4
  • o-o-sec: 2.4.9.4-0+deb11u6
  • oldstable: 2.4.12.3-2+deb12u4
  • old-sec: 2.4.12.3-2+deb12u4
  • stable: 2.4.17-1
  • testing: 2.4.19.4-1
  • unstable: 2.4.20.2-1
versioned links
  • 2.4.9.4-0+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.9.4-0+deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.12.3-2+deb12u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.17-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.19.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.4.20.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libapache2-mod-auth-openidc
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-54789: mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.
Created: 2026-08-22 Last update: 2026-08-27 18:01
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-54789: mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.
Created: 2026-08-22 Last update: 2026-08-27 18:01
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-54789: mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.
Created: 2026-08-22 Last update: 2026-08-27 18:01
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for libapache2-mod-auth-openidc (2.4.19.4-1 to 2.4.20.2-1): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for freedombox/26.10: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for libapache2-mod-auth-openidc/2.4.20.2-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/liba/libapache2-mod-auth-openidc.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-08-27] Accepted libapache2-mod-auth-openidc 2.4.20.2-1 (source) into unstable (Moritz Schlarb)
  • [2026-07-08] libapache2-mod-auth-openidc 2.4.19.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-06] Accepted libapache2-mod-auth-openidc 2.4.19.4-1 (source) into unstable (Moritz Schlarb)
  • [2026-07-06] Accepted libapache2-mod-auth-openidc 2.4.19.2-3 (source) into unstable (Moritz Schlarb)
  • [2026-07-06] Accepted libapache2-mod-auth-openidc 2.4.19.2-2 (source) into unstable (Moritz Schlarb)
  • [2026-03-16] libapache2-mod-auth-openidc 2.4.19.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-13] Accepted libapache2-mod-auth-openidc 2.4.19.2-1 (source) into unstable (Moritz Schlarb)
  • [2026-02-20] libapache2-mod-auth-openidc 2.4.19.1-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-12] Accepted libapache2-mod-auth-openidc 2.4.19.1-2 (source) into unstable (Moritz Schlarb)
  • [2026-02-12] Accepted libapache2-mod-auth-openidc 2.4.19.1-1 (source) into unstable (Moritz Schlarb)
  • [2026-01-02] Accepted libapache2-mod-auth-openidc 2.4.19-1 (source) into unstable (Moritz Schlarb)
  • [2025-10-08] libapache2-mod-auth-openidc 2.4.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-06] Accepted libapache2-mod-auth-openidc 2.4.18.1-1 (source) into unstable (Moritz Schlarb)
  • [2025-08-25] libapache2-mod-auth-openidc 2.4.18-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-22] Accepted libapache2-mod-auth-openidc 2.4.18-1 (source) into unstable (Moritz Schlarb)
  • [2025-08-17] libapache2-mod-auth-openidc 2.4.17.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-12] Accepted libapache2-mod-auth-openidc 2.4.17.2-1 (source) into unstable (Moritz Schlarb)
  • [2025-05-09] Accepted libapache2-mod-auth-openidc 2.4.12.3-2+deb12u4 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Schlarb)
  • [2025-05-08] Accepted libapache2-mod-auth-openidc 2.4.12.3-2+deb12u4 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Schlarb)
  • [2025-05-08] Accepted libapache2-mod-auth-openidc 2.4.9.4-0+deb11u6 (source) into oldstable-security (Moritz Schlarb)
  • [2025-05-02] libapache2-mod-auth-openidc 2.4.17-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-22] Accepted libapache2-mod-auth-openidc 2.4.17-1 (source) into unstable (Moritz Schlarb)
  • [2025-04-18] Accepted libapache2-mod-auth-openidc 2.4.12.3-2+deb12u3 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Schlarb)
  • [2025-04-17] Accepted libapache2-mod-auth-openidc 2.4.12.3-2+deb12u3 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Schlarb)
  • [2025-04-17] Accepted libapache2-mod-auth-openidc 2.4.9.4-0+deb11u5 (source) into oldstable-security (Moritz Schlarb)
  • [2025-04-12] libapache2-mod-auth-openidc 2.4.16.11-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-10] Accepted libapache2-mod-auth-openidc 2.4.16.11-1 (source) into unstable (Moritz Schlarb)
  • [2025-03-23] libapache2-mod-auth-openidc 2.4.16.10-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-22] libapache2-mod-auth-openidc 2.4.16.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-21] Accepted libapache2-mod-auth-openidc 2.4.16.10-1 (source) into unstable (Moritz Schlarb)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.4.19.4-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing