#ChannelBinding
📌 CVE-2026-54291 - pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded fro... https://www.cyberhub.blog/cves/CVE-2026-54291
CVE-2026-54291
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee
www.cyberhub.blog
July 19, 2026 at 10:07 PM
Feed: "PostgreSQL news"
Published on Monday, July 6, 2026
PostgreSQL JDBC 42.7.12 Security Release
Silent channel-binding authentication downgrade (CVE-2026-54291) channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (wi...
www.postgresql.org
July 7, 2026 at 1:36 AM
🚨 EUVD-2026-41903
📊 8.2/10
🏢 pgjdbc

📝 pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCR...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41903

#cybersecurity #infosec #cve #euvd
July 6, 2026 at 8:00 PM
CVE-2026-54291 - Silent channel-binding authentication downgrade via unsupported certificate algorithms
CVE ID : CVE-2026-54291

Published : July 6, 2026, 7:17 p.m. | 31 minutes ago

Description : pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through ...
CVE-2026-54291 - Silent channel-binding authentication downgrade via unsupported certificate algorithms
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the …
cvefeed.io
July 6, 2026 at 8:36 PM