Cross-site request forgery in mod_auth_openidc - #VU142423
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to influence authorization request parameters.
The vulnerability exists due to improper request validation in discovery response parameter handling when processing discovery responses without a valid CSRF check. A remote attacker can cause the victim\'s browser to submit crafted discovery response parameters to influence authorization request parameters.
This affects scopes and authorization request parameters carried on the discovery response.