mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9, the AES GCM encryption in mod_auth_openidc uses a static IV and AAD. It is important to fix because this creates a static nonce and since aes-gcm is a stream cipher, this can lead to known cryptographic issues, since the same key is being reused. From 2.4.9 onwards this has been patched to use dynamic values through usage of cjose AES encryption routines.
Conclusion & alert: CVE-2021-32791 is rated Moderate Risk (47.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.51%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-28 | 0.36% | 0.51% | +0.15% |
| 2 | 2026-05-02 | 0.35% | 0.36% | +0.01% |
| 3 | 2026-01-20 | — | 0.35% | — |
Full EPSS history (33 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-32791 not yet assigned priority: Debian including 1 source packages (libapache2-mod-auth-openidc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-32791 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-32791 |
suse
|
medium | CVE-2021-32791 severity moderate: SUSE including 7 source package names (apache2-mod_auth_openidc-2.3.8-3.15.1, apache2-mod_auth_openidc-2.3.8-lp152.5.6.1, …), 14 product×package rows across 12 product lines (SUSE Liberty Linux 8, SUSE Linux Enterprise Module for Server Applications 15 SP2, … (12 product lines)): Fixed 14. | https://www.suse.com/security/cve/CVE-2021-32791/ |
ubuntu
|
low | CVE-2021-32791 low priority: Ubuntu including 1 source packages (libapache2-mod-auth-openidc), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 10, needed 2, DNE 1, ignored 1, released 1. | https://ubuntu.com/security/CVE-2021-32791 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openidc | mod_auth_openidc | < 2.4.9 | cpe:2.3:a:openidc:mod_auth_openidc:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |