Critical severityNVD Advisory· Published Apr 21, 2026· Updated Apr 22, 2026
CVE-2026-40946
CVE-2026-40946
Description
Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/oxia-db/oxiaGo | < 0.16.2 | 0.16.2 |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.