{"id":"GHSA-p9jg-fcr6-3mhf","summary":"OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms","details":"## Summary\n\nA flaw in `com.ongres.scram:scram-client` allows an attacker capable of performing a TLS man-in-the-middle (MITM) attack to silently downgrade a connection from `SCRAM-SHA-256-PLUS` (with channel binding) to standard `SCRAM-SHA-256` (without channel binding), bypassing strict client-side enforcement policies.\n\n## Component Breakdown\n\nThis occurs due to a two-part failure in `TlsServerEndpoint` when a server presents an `X.509` certificate using a modern signature algorithm that lacks traditional `WITH` naming structures (such as `Ed25519` or post-quantum algorithms):\n\n1. The internal hash derivation method fails to parse the algorithm name, swallows the resulting `NoSuchAlgorithmException, and silently returns an empty byte array via the deprecated `getChannelBindingData()` API.\n2. The client builder mistakenly interprets this empty byte array as an environmental absence of channel binding data rather than a cryptographic failure, falling back to non-channel-bound authentication.\n\n## Impact & Scope\n\nThis issue only impacts deployments where the downstream application layer explicitly enforces strict channel binding enforcement (e.g., channelBinding=require in pgJDBC).\n\nDrivers operating under a \"prefer\" or \"allow\" policy  (used by default) are structurally insulated from an unhandled exception since a fallback to standard SCRAM is within their expected configuration.\n\n## Remediation\n\nUpdate your project configuration to pull in version 3.3 or later of the SCRAM library, which introduces strict exception propagation and explicit policy controls.\n\nIf you are interacting with the `ScramClient` builder API directly (e.g., writing a custom driver or database extension):\n\n- Migrate Deprecated APIs: Stop using `TlsServerEndpoint.getChannelBindingData()`. Transition immediately to `TlsServerEndpoint.getChannelBindingHash()`, which correctly propagates `NoSuchAlgorithmException` up the stack.\n- Adopt Explicit Policies: Leverage the newly introduced `ChannelBindingPolicy` API during client construction. Do not rely on implicit parameter presence to dictate your security boundaries.\n\n```java\nScramClient client = ScramClient.builder()\n    .advertisedMechanisms(serverMechanisms)\n    .username(user)\n    .password(pass)\n    // Explicitly enforce strict boundaries if needed.\n    .channelBindingPolicy(ChannelBindingPolicy.REQUIRE) \n    .channelBinding(TlsServerEndpoint.TLS_SERVER_END_POINT, certHash)\n    .build();\n```","aliases":["CVE-2026-53712"],"modified":"2026-08-24T00:37:06.828479734Z","published":"2026-07-01T21:51:17Z","database_specific":{"cwe_ids":["CWE-636","CWE-757"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-01T21:51:17Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf"},{"type":"PACKAGE","url":"https://github.com/ongres/scram"}],"affected":[{"package":{"name":"com.ongres.scram:scram-client","ecosystem":"Maven","purl":"pkg:maven/com.ongres.scram/scram-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3"}]}],"versions":["3.0","3.1","3.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p9jg-fcr6-3mhf/GHSA-p9jg-fcr6-3mhf.json"}},{"package":{"name":"com.ongres.scram:scram-common","ecosystem":"Maven","purl":"pkg:maven/com.ongres.scram/scram-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3"}]}],"versions":["3.0","3.1","3.2"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-p9jg-fcr6-3mhf/GHSA-p9jg-fcr6-3mhf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N"}]}