GHSA-fhvp-9hcj-6m33

Suggest an improvement
Source
https://github.com/advisories/GHSA-fhvp-9hcj-6m33
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fhvp-9hcj-6m33/GHSA-fhvp-9hcj-6m33.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-fhvp-9hcj-6m33
Aliases
Published
2026-04-14T23:14:49Z
Modified
2026-06-25T19:56:21Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Oxia has an OIDC token audience validation bypass via SkipClientIDCheck
Details

Summary

The OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia.

Impact

In deployments using OIDC authentication, an attacker possessing a valid JWT token issued by the same identity provider but intended for a different service (different client_id/aud) can authenticate to Oxia. This bypasses the intended audience isolation of OAuth2/OIDC.

All versions using OIDC authentication are affected.

Details

In oxiad/common/rpc/auth/oidc.go, both createStaticKeyVerifier() and createRemoteVerifier() set SkipClientIDCheck: true. While a custom audience check exists in Authenticate(), the library-level check — which validates the aud claim against the expected client_id — is completely bypassed.

Patches

Fixed by removing SkipClientIDCheck: true and setting the ClientID field from the configured AllowedAudiences.

Workarounds

Ensure network-level isolation so that only trusted services can reach the Oxia gRPC endpoints.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-14T23:14:49Z",
    "nvd_published_at": "2026-04-21T22:16:20Z",
    "severity": "CRITICAL"
}
References

Affected packages

Go / github.com/oxia-db/oxia

Package

Name
github.com/oxia-db/oxia
View open source insights on deps.dev
Purl
pkg:golang/github.com/oxia-db/oxia

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.16.2

Database specific

last_known_affected_version_range
"<= 0.16.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fhvp-9hcj-6m33/GHSA-fhvp-9hcj-6m33.json"