GHSA-7jrq-q4pq-rhm6

Suggest an improvement
Source
https://github.com/advisories/GHSA-7jrq-q4pq-rhm6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-7jrq-q4pq-rhm6/GHSA-7jrq-q4pq-rhm6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-7jrq-q4pq-rhm6
Aliases
Published
2026-04-14T23:15:16Z
Modified
2026-06-25T19:56:14Z
Severity
  • 8.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Oxia's TLS CA certificate chain validation fails with multi-certificate PEM bundles
Details

Summary

The trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS.

Impact

In deployments using mTLS with certificate chains (intermediate CA + root CA bundles), legitimate clients with properly chained certificates are rejected with x509: certificate signed by unknown authority. This degrades the security posture by making mTLS unusable with standard CA chain configurations, potentially forcing operators to disable client certificate verification.

All versions using TLS with trustedCaFile configuration are affected.

Details

In common/security/tls.go, the trustedCertPool() method calls pem.Decode() only once, processing a single PEM block. The remaining bytes (containing additional certificates) are silently discarded. Additionally, the error return from pem.Decode is ignored, so a corrupted CA file results in an empty certificate pool without any error.

Patches

Fixed by iterating over all PEM blocks in the file, parsing each CERTIFICATE block, and returning an error if no valid certificates are found.

Workarounds

Use CA files containing only a single certificate (the direct issuer of client certificates, not a chain).

Database specific
{
    "cwe_ids":  [
        "CWE-295"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-14T23:15:16Z",
    "nvd_published_at":  "2026-04-21T22:16:19Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / github.com/oxia-db/oxia

Package

Name
github.com/oxia-db/oxia
View open source insights on deps.dev
Purl
pkg:golang/github.com/oxia-db/oxia

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.16.2

Database specific

last_known_affected_version_range
"<= 0.16.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-7jrq-q4pq-rhm6/GHSA-7jrq-q4pq-rhm6.json"