CVE-2026-53712

SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack to silently downgrade a connection from SCRAM-SHA-256-PLUS with channel binding to standard SCRAM-SHA-256 without channel binding when TlsServerEndpoint processes an X.509 certificate using a modern signature algorithm such as Ed25519; getChannelBindingData() can return an empty byte array after NoSuchAlgorithmException, and the ScramClient builder treats that as absent channel-binding data. This issue is fixed in version 3.3.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-17 19:17

Updated : 2026-07-23 16:15


NVD link : CVE-2026-53712

Mitre link : CVE-2026-53712

CVE.ORG link : CVE-2026-53712


JSON object : View

Products Affected

No product.

CWE
CWE-636

Not Failing Securely ('Failing Open')

CWE-757

Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')