Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-04-21 22:16
Updated : 2026-06-17 10:45
NVD link : CVE-2026-40946
Mitre link : CVE-2026-40946
CVE.ORG link : CVE-2026-40946
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
