oxia是Oxia开源的一个分布式元数据存储与协调系统。 Oxia 0.16.2之前版本存在授权问题漏洞,该漏洞源于OIDC身份验证提供程序无条件地在go-oidc验证器配置中设置SkipClientIDCheck: true,禁用了库级别的标准受众声明验证,可能导致同一OIDC颁发者为无关服务颁发的令牌被Oxia接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40943 | Oxia: Server crash via race condition in session heartbeat handling | |
| CVE-2026-40945 | Oxia: Bearer token exposed in debug log messages on authentication failure | |
| CVE-2026-40944 | Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles |
No comments yet