CVE 9.2 CRITICAL

Oxia: OIDC token audience validation bypass via SkipClientIDCheck_CVE-2026-40946

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.

AI Analysis

OIDC token audience validation bypass via SkipClientIDCheck

Basic Information

ID CVE-2026-40946
Source GitHub_M
Published Apr 21, 2026 at 21:18

Affected Product

Vendor oxia-db
Product oxia
Version < 0.16.2
Affected Versions oxia-db oxia < 0.16.2

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor oxia-db
Product Oxia
Version < 0.16.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.