You’ve already isolated it to the OIDC SSO, but if you’d like to fix the issue for the time being, you can open up settings on the OIDC module, and change the dependency library to fix this. Looks like OIDC still has the apache web group name here, just change it to commons-codec and it worked for me.
The new version of the OIDC SSO module (v2.3.1 from Nov 15) has solved the issue in a systemic way.