<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:34:49.670912+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338583</id>
    <title>EUVD-2026-338583</title>
    <updated>2026-10-02T15:34:49.787964+00:00</updated>
    <content>EUVD-2026-338583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53712</id>
    <title>fkie_cve-2026-53712</title>
    <updated>2026-10-02T15:34:49.788009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack to silently downgrade a connection from SCRAM-SHA-256-PLUS with channel binding to standard SCRAM-SHA-256 without channel binding when TlsServerEndpoint processes an X.509 certificate using a modern signature algorithm such as Ed25519; getChannelBindingData() can return an empty byte array after NoSuchAlgorithmException, and the ScramClient builder treats that as absent channel-binding data. This issue is fixed in version 3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p9jg-fcr6-3mhf</id>
    <title>GHSA-p9jg-fcr6-3mhf — OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms</title>
    <updated>2026-10-02T15:34:49.788047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.ongres.scram:scram-client, Maven: com.ongres.scram:scram-common</p>
<p>## Summary</p>
<p>A flaw in `com.ongres.scram:scram-client` allows an attacker capable of performing a TLS man-in-the-middle (MITM) attack to silently downgrade a connection from `SCRAM-SHA-256-PLUS` (with channel binding) to standard `SCRAM-SHA-256` (without channel binding), bypassing strict client-side enforcement policies.</p>
<p>## Component Breakdown</p>
<p>This occurs due to a two-part failure in `TlsServerEndpoint` when a server presents an `X.509` certificate using a modern signature algorithm that lacks traditional `WITH` naming structures (such as `Ed25519` or post-quantum algorithms):</p>
<p>1. The internal hash derivation method fails to parse the algorithm name, swallows the resulting `NoSuchAlgorithmException, and silently returns an empty byte array via the deprecated `getChannelBindingData()` API.
2. The client builder mistakenly interprets this empty byte array as an environmental absence of channel binding data rather than a cryptographic failure, falling back to non-channel-bound authentication.</p>
<p>## Impact &amp; Scope</p>
<p>This issue only impacts deployments where the downstream application layer explicitly enforces strict channel binding enforcement (e.g., channelBinding=require in pgJDBC).</p>
<p>Drivers operating under a "prefer" or "allow" policy  (used by default) are structurally insulated from an unhandled exception since a fallback to standard SCRAM is within their expected configuration.</p>
<p>## Remediation</p>
<p>Update your project configuration to pull in version 3.3 or later of the SCRAM l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p9jg-fcr6-3mhf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:51653</id>
    <title>RHSA-2026:51653 — Red Hat Security Advisory: Red Hat build of Quarkus 3.33.3 release and security update</title>
    <updated>2026-10-02T15:34:49.788101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jansi: org.fusesource.jansi/jansi: Jansi: Heap buffer overflow leads to Denial of Service com.ongres.scram/scram-client: com.ongres.scram/scram-common: SCRAM Libraries: Authentication downgrade via TLS man-in-the-middle attack org.postgresql/postgresql: com.ongres.scram/scram-client: pgjdbc: Man-in-the-middle protection bypass via SCRAM-SHA-256-PLUS downgrade org.apache.sshd/sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:51653"/>
  </entry>
</feed>
