CVE-2026-40944

MEDIUM

Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles

Title source: cna
STIX 2.1

Description

Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.

Scores

CVSS v4 6.9
EPSS 0.0003
EPSS Percentile 8.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (1)
oxia-db/oxia < 0.16.2
Published Apr 21, 2026
Tracked Since Apr 22, 2026