{"id":"CLSA-2025-1746655009","summary":"mod_auth_openidc: Fix of CVE-2024-24814","details":"- CVE-2024-24814: fix DoS when `OIDCSessionType client-cookie` is set and\n  a crafted Cookie header is supplied","modified":"2026-05-27T11:16:45.103339507Z","published":"2025-05-07T21:56:54Z","upstream":["CVE-2024-24814"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/almalinux9.2-esu/CLSA-2025-1746655009.html"}],"affected":[{"package":{"name":"mod_auth_openidc","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/mod_auth_openidc?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.9.4-1.el9.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1746655009.json"}}],"schema_version":"1.7.5"}