Back to search
CVE-2026-40946
Published: Apr 21, 2026
Modified: Apr 22, 2026
PUBLISHED
Description
Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.
| Vendor | Product | Versions |
|---|---|---|
oxia-db | oxia | affected < 0.16.2 |
Weaknesses (CWE)
References
https://github.com/oxia-db/oxia/security/advisories/GHSA-fhvp-9hcj-6m33
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now