Loading
Generated remediation guidance and an executive summary. No account required.
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.
No affected products information available.
Use CWE-295 to widen CVE-2026-40944 into its surrounding weakness, vendor, and product context.