PT-2026-34187 · Oxia · Oxia

CVE-2026-40943

·

Published

2026-04-14

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Oxia versions prior to 0.16.2
Description A race condition exists between session heartbeat processing and session closure. The heartbeat() method utilizes a blocking channel send while holding a mutex. Under specific timing with concurrent close() calls, this can result in a deadlock if the channel buffer is full, or a server panic due to a send on a closed channel following a Time-of-Check to Time-of-Use (TOCTOU) gap in KeepAlive. TOCTOU is a software bug where a system checks the state of a resource before using it, but the state changes between the check and the use.
Recommendations Update to version 0.16.2.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40943
GHSA-5GQC-QHRJ-9XW8
GO-2026-5145
OPENSUSE-SU-2026:21483-1

Affected Products

Oxia