HIGH
Oxia: Bearer token exposed in debug log messages on authentication failure
Published Apr 21, 2026
8.7
HIGHCVSS 4.0
EPSS 0.54%
Description
Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulnerability is fixed in 0.16.2.
Affected products
-
- Version < 0.16.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/oxia-db/oxia
Go
Introduced 0 Fixed 0.16.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/oxia-db/oxia | 0 | 0.16.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24511 Advisory
- https://github.com/advisories/GHSA-pm7q-rjjx-979p Advisory
- https://github.com/oxia-db/oxia/commit/f7259d0ebc739fc95ff19f93c823433850857416
- https://github.com/oxia-db/oxia/security/advisories/GHSA-pm7q-rjjx-979p x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-40945
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Reserved Apr 15, 2026
Link CVE-2026-40945
CISA Vulnrichment
Updated Apr 22, 2026
ENISA EUVD
EUVD-2026-24511 GHSA-PM7Q-RJJX-979P Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Exploited since n/a
Link EUVD-2026-24511