All 4 CVE vulnerabilities found in oxia, with AI-generated Chinese analysis, references, and POCs.
Vendor: oxia-db
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-40946 | Oxia: OIDC token audience validation bypass via SkipClientIDCheck CWE-287 | 9.1AI | CriticalAI | 2026-04-21 |
| CVE-2026-40945 | Oxia: Bearer token exposed in debug log messages on authentication failure CWE-532 | 7.5AI | HighAI | 2026-04-21 |
| CVE-2026-40944 | Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles CWE-295 | 7.5AI | HighAI | 2026-04-21 |
| CVE-2026-40943 | Oxia: Server crash via race condition in session heartbeat handling CWE-362 | 5.9AI | MediumAI | 2026-04-21 |
All 4 known CVE vulnerabilities affecting oxia with full Chinese analysis, references, and POCs where available.