BRIEFING NOTE: CVE-2026-40944 Oxia versions prior to 0.16.2 contain a vulnerability in the trustedCertPool() function where TLS configuration parsing only reads the first PEM block from CA certificate files. This flaw prevents proper loading of certificate chains containing multiple certificates such as intermediate and root CAs, silently breaking mutual TLS (mTLS) certificate chain validation for systems relying on bundled CA certificates. The vulnerability poses moderate security risk with a FAUCET Risk Score of 36.0/100. While specific CVSS vector details are unavailable, the issue represents a logic flaw that silently undermines cryptographic authentication mechanisms. The attack surface depends on whether an attacker can exploit the validation bypass, though the exact attack complexity and prerequisites remain unspecified in available data. This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. Community attention appears minimal given the low EPSS score of 0.0002, suggesting limited real-world prevalence or impact. Organizations using Oxia should upgrade to version 0.16.2 or later to restore proper certificate chain validation for mTLS connections.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Oxia-Db | Oxia | < 0.16.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.