PT-2026-34189 · Oxia · Oxia

Published

2026-04-14

·

Updated

2026-04-26

·

CVE-2026-40945

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Oxia versions prior to 0.16.2
Description When OIDC (OpenID Connect, an identity layer on top of the OAuth 2.0 protocol) authentication fails, the full bearer token is logged in plaintext at the DEBUG level. If debug logging is enabled in production, JWT (JSON Web Tokens) are exposed in application logs and any connected log aggregation system.
Recommendations Update to version 0.16.2.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2026-40945
GHSA-PM7Q-RJJX-979P

Affected Products

Oxia