CVE-2026-40944
MEDIUMOxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles
Title source: cnaDescription
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.
Scores
CVSS v4
6.9
EPSS
0.0003
EPSS Percentile
8.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (1)
oxia-db/oxia
< 0.16.2
Published
Apr 21, 2026
Tracked Since
Apr 22, 2026