Com.ongres.scram:scram client: OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms (CVE-2026-53712)
A vulnerability in com.ongres.scram:scram-client versions prior to 3.3 allows a TLS man-in-the-middle attacker to silently downgrade SCRAM authentication from SCRAM-SHA-256-PLUS (with channel binding) to SCRAM-SHA-256 (without channel binding). This occurs when the server presents an X.509 certificate using modern signature algorithms that the client cannot parse properly, causing fallback to a less secure authentication method without error. This can bypass strict channel binding policies in affected deployments.
AI Analysis
Technical Summary
The com.ongres.scram:scram-client library versions before 3.3 contain a vulnerability (CVE-2026-53712) where a TLS man-in-the-middle attacker can cause a silent downgrade of SCRAM authentication from SCRAM-SHA-256-PLUS, which includes channel binding, to SCRAM-SHA-256 without channel binding. This happens because the client fails to parse certain modern X.509 certificate signature algorithms correctly and falls back to non-channel-bound authentication without alerting the user. This undermines security controls that rely on strict channel binding enforcement.
Potential Impact
This vulnerability allows an attacker positioned as a man-in-the-middle on the TLS channel to bypass channel binding protections by downgrading the authentication method silently. This reduces the security guarantees of the SCRAM authentication process, potentially allowing unauthorized access or session hijacking in environments that enforce strict channel binding policies.
Mitigation Recommendations
No official patch or fix is currently documented. Users should upgrade to version 3.3 or later once available, as versions prior to 3.3 are affected. Until a fix is released, consider avoiding use of affected versions in environments requiring strict channel binding enforcement or monitor for updates from the vendor. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Com.ongres.scram:scram client: OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms (CVE-2026-53712)
Description
A vulnerability in com.ongres.scram:scram-client versions prior to 3.3 allows a TLS man-in-the-middle attacker to silently downgrade SCRAM authentication from SCRAM-SHA-256-PLUS (with channel binding) to SCRAM-SHA-256 (without channel binding). This occurs when the server presents an X.509 certificate using modern signature algorithms that the client cannot parse properly, causing fallback to a less secure authentication method without error. This can bypass strict channel binding policies in affected deployments.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The com.ongres.scram:scram-client library versions before 3.3 contain a vulnerability (CVE-2026-53712) where a TLS man-in-the-middle attacker can cause a silent downgrade of SCRAM authentication from SCRAM-SHA-256-PLUS, which includes channel binding, to SCRAM-SHA-256 without channel binding. This happens because the client fails to parse certain modern X.509 certificate signature algorithms correctly and falls back to non-channel-bound authentication without alerting the user. This undermines security controls that rely on strict channel binding enforcement.
Potential Impact
This vulnerability allows an attacker positioned as a man-in-the-middle on the TLS channel to bypass channel binding protections by downgrading the authentication method silently. This reduces the security guarantees of the SCRAM authentication process, potentially allowing unauthorized access or session hijacking in environments that enforce strict channel binding policies.
Mitigation Recommendations
No official patch or fix is currently documented. Users should upgrade to version 3.3 or later once available, as versions prior to 3.3 are affected. Until a fix is released, consider avoiding use of affected versions in environments requiring strict channel binding enforcement or monitor for updates from the vendor. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p9jg-fcr6-3mhf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53712"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a45998227e9c797194186f1
Added to database: 07/01/2026, 22:49:38 UTC
Last enriched: 07/18/2026, 11:19:27 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 117
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.