TLS Configuration Vulnerability in Oxia Metadata Store by Oxia
CVE-2026-40944
6.9MEDIUM
What is CVE-2026-40944?
The Oxia Metadata Store prior to version 0.16.2 contains a vulnerability in its TLS configuration related to the trustedCertPool() function. This issue arises because the function only processes the first PEM block from CA certificate files, leading to incomplete certificate loading from bundles that contain multiple certificates. As a result, mTLS validation fails silently, breaking the integrity of the certificate chain. This vulnerability can pose significant security risks, as it undermines the expected certificate validation process essential for secure communications.
Affected Version(s)
oxia < 0.16.2
