Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40944

22
FAUCET Score

BRIEFING NOTE: CVE-2026-40944 Oxia versions prior to 0.16.2 contain a vulnerability in the trustedCertPool() function where TLS configuration parsing only reads the first PEM block from CA certificate files. This flaw prevents proper loading of certificate chains containing multiple certificates such as intermediate and root CAs, silently breaking mutual TLS (mTLS) certificate chain validation for systems relying on bundled CA certificates. The vulnerability poses moderate security risk with a FAUCET Risk Score of 36.0/100. While specific CVSS vector details are unavailable, the issue represents a logic flaw that silently undermines cryptographic authentication mechanisms. The attack surface depends on whether an attacker can exploit the validation bypass, though the exact attack complexity and prerequisites remain unspecified in available data. This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. Community attention appears minimal given the low EPSS score of 0.0002, suggesting limited real-world prevalence or impact. Organizations using Oxia should upgrade to version 0.16.2 or later to restore proper certificate chain validation for mTLS connections.

Impacted Technologies

VendorProductVersion(s)CPE
Oxia-DbOxia
< 0.16.2CNA affected

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 1st percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/oxia-db/oxiaFixed in: 0.16.2

Vendor Advisories (1)

goGHSA-7jrq-q4pq-rhm6high

Oxia's TLS CA certificate chain validation fails with multi-certificate PEM bundles

Apr 14, 2026

References

github.com / oxia-db/oxia/security/advisories/GHSA-7jrq-q4pq-rhm6