Back

HIGH

Oxia: Bearer token exposed in debug log messages on authentication failure

Published Apr 21, 2026

Description

Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulnerability is fixed in 0.16.2.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Reserved Apr 15, 2026
CISA Vulnrichment
Updated Apr 22, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Exploited since n/a
EUVD-2026-24511 GHSA-PM7Q-RJJX-979P