> Debian libapache2-mod-auth-openidc Key Denial of Service Patch DSA-6504-1
[DATE: 17/09/2026 18:14]
[LANGUAGE: EN]
It was discovered that incorrect state cookie parsing in mod_auth_openidc, an OpenID Certified authentication and authorisation module for the Apache HTTP server that implements the OpenID Connect Relying Party functionality, could result in denial of service. For the stable distribution (trixie), this problem has been fixed in