OIDC Authentication Logging Vulnerability in Oxia Metadata Store
CVE-2026-40945

8.7HIGH

Key Information:

Vendor

Oxia-db

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-40945?

The Oxia Metadata Store, prior to version 0.16.2, contains a vulnerability that exposes the full bearer token in plaintext within application logs when OIDC authentication fails. This occurs specifically when debug logging is enabled in production environments, leading to potential leakage of sensitive information, such as JWT tokens, which may be accessible through connected log aggregation systems. This critical security oversight has been addressed in version 0.16.2.

Affected Version(s)

oxia < 0.16.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.