Cross-site scripting in mod_auth_openidc - #VU142422
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in the victim\'s browser.
The vulnerability exists due to cross-site scripting in module-generated pages when rendering unescaped values into HTML attributes. A remote attacker can supply crafted redirect URI or provider metadata values to execute arbitrary script in the victim\'s browser.
This affects the discovery page and the auto-POST form, and exploitation requires a relative OIDCRedirectURI or attacker-influenced provider metadata.