Inclusion of Sensitive Information in Log Files in mod_auth_openidc - #VU142427
Published: August 13, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive credentials from debug logs.
The vulnerability exists due to insertion of sensitive information into log files in debug logging of provider responses and cookie values when writing unredacted response data to logs. A local user can read debug logs to disclose sensitive credentials from debug logs.
This includes tokens, client secrets, registration access tokens, and cookie values, and requires debug logging and log access.