<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:38:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292606</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292606</link>
      <description>EUVD-2026-292606</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292606</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40945</link>
      <description>&lt;p&gt;Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulnerability is fixed in 0.16.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulnerability is fixed in 0.16.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40945</guid>
    </item>
    <item>
      <title>GHSA-pm7q-rjjx-979p — Oxia exposes bearer token in debug log messages on authentication failure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pm7q-rjjx-979p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/oxia-db/oxia&lt;/p&gt;
&lt;p&gt;### Summary
When OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker with access to application logs (e.g., via a compromised log aggregation pipeline, shared logging infrastructure, or misconfigured log access controls) can extract valid JWT tokens and replay them to authenticate as legitimate users.&lt;/p&gt;
&lt;p&gt;All versions using OIDC authentication are affected.&lt;/p&gt;
&lt;p&gt;### Details
In `oxiad/common/rpc/auth/interceptor.go`, the `validateTokenWithContext()` function logs the complete token value via `slog.String(&amp;#34;token&amp;#34;, token)` when authentication fails. This includes the full JWT header, payload, and signature.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed by redacting the token in log output — only the last 8 characters are preserved for correlation purposes.&lt;/p&gt;
&lt;p&gt;### Workarounds
Ensure DEBUG-level logging is never enabled in production environments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/oxia-db/oxia&lt;/p&gt;
&lt;p&gt;### Summary
When OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system.&lt;/p&gt;
&lt;p&gt;### Impact
An attacker with access to application logs (e.g., via a compromised log aggregation pipeline, shared logging infrastructure, or misconfigured log access controls) can extract valid JWT tokens and replay them to authenticate as legitimate users.&lt;/p&gt;
&lt;p&gt;All versions using OIDC authentication are affected.&lt;/p&gt;
&lt;p&gt;### Details
In `oxiad/common/rpc/auth/interceptor.go`, the `validateTokenWithContext()` function logs the complete token value via `slog.String(&amp;#34;token&amp;#34;, token)` when authentication fails. This includes the full JWT header, payload, and signature.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed by redacting the token in log output — only the last 8 characters are preserved for correlation purposes.&lt;/p&gt;
&lt;p&gt;### Workarounds
Ensure DEBUG-level logging is never enabled in production environments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pm7q-rjjx-979p</guid>
    </item>
  </channel>
</rss>
