TLS Configuration Vulnerability in Oxia Metadata Store by Oxia
CVE-2026-40944

6.9MEDIUM

Key Information:

Vendor

Oxia-db

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40944?

The Oxia Metadata Store prior to version 0.16.2 contains a vulnerability in its TLS configuration related to the trustedCertPool() function. This issue arises because the function only processes the first PEM block from CA certificate files, leading to incomplete certificate loading from bundles that contain multiple certificates. As a result, mTLS validation fails silently, breaking the integrity of the certificate chain. This vulnerability can pose significant security risks, as it undermines the expected certificate validation process essential for secure communications.

Affected Version(s)

oxia < 0.16.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.