CVE-2026-40944: Oxia-DB Oxia
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.
Affected products
- Oxia-DB Oxia: before 0.16.2 (fixed in 0.16.2)
Published 2026-04-21. Last modified 2026-06-17.