CVE Explorer
CVE-2026-40944
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"oxia","vendor":"oxia-db","versions":[{"status":"affected","version":"< 0.16.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c0e83c226072cdc2b61428638732bf37942ffe10035cc7dd2ce74588e345d40d · sha256:eeb50b0977a139cf… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c0e83c226072cdc2b61428638732bf37942ffe10035cc7dd2ce74588e345d40d · sha256:eeb50b0977a139cf… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-295","description":"CWE-295: Improper Certificate Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c0e83c226072cdc2b61428638732bf37942ffe10035cc7dd2ce74588e345d40d · sha256:eeb50b0977a139cf… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/oxia-db/oxia/security/advisories/GHSA-7jrq-q4pq-rhm6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/oxia-db/oxia/security/advisories/GHSA-7jrq-q4pq-rhm6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c0e83c226072cdc2b61428638732bf37942ffe10035cc7dd2ce74588e345d40d · sha256:eeb50b0977a139cf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.