Bug 2442908 (CVE-2026-27830)

Summary: CVE-2026-27830 c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abrianik, anthomas, anujha, asoldano, bbaranow, bmaxwell, brian.stansberry, bstansbe, ccranfor, chfoley, darran.lofthouse, dhanak, dlofthou, dosoudil, drosa, ehelms, fjuma, fmariani, ggainey, ggrzybek, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jpasqual, jpechane, jraez, jrokos, jscholz, juwatts, jwon, kgaikwad, kverlaen, mcarlett, mdellweg, mhulan, mnovotny, mosmerov, msvehla, nmoumoul, nwallace, osousa, parichar, pberan, pcreech, pdelbell, pesilva, pjindal, pmackay, rchan, rgodfrey, rstancel, rstepani, sausingh, smaestri, smallamp, swoodman, tasato, tcunning, thjenkin, tmalecek, tom.jenkinson, vdosoudi, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in c3p0, a Java Database Connectivity (JDBC) Connection pooling library. This vulnerability allows an attacker to achieve arbitrary code execution by providing maliciously crafted Java-serialized objects or `javax.naming.Reference` instances. By manipulating the `userOverridesAsString` property, an attacker can cause the application to download and execute malicious code from a remote location on its CLASSPATH.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-02-26 01:02:21 UTC
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects "indirectly serialized" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, represents a serious independent fragility. The `userOverridesAsString` property of c3p0 `ConnectionPoolDataSource` classes has been reimplemented to use a safe CSV-based format, rather than rely upon potentially dangerous Java object deserialization. c3p0-0.12.0+ and above depend upon mchange-commons-java 0.4.0+, which gates support for remote `factoryClassLocation` values by configuration parameters that default to restrictive values. c3p0 additionally enforces the new mchange-commons-java `com.mchange.v2.naming.nameGuardClassName` to prevent injection of unexpected, potentially remote JNDI names. There is no supported workaround for versions of c3p0 prior to 0.12.0.

Comment 2 errata-xmlrpc 2026-03-05 13:32:54 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11

Via RHSA-2026:3890 https://access.redhat.com/errata/RHSA-2026:3890

Comment 3 errata-xmlrpc 2026-05-18 12:12:24 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:18059 https://access.redhat.com/errata/RHSA-2026:18059

Comment 4 errata-xmlrpc 2026-05-18 12:18:59 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:18055 https://access.redhat.com/errata/RHSA-2026:18055

Comment 5 errata-xmlrpc 2026-05-18 12:21:53 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:18054 https://access.redhat.com/errata/RHSA-2026:18054

Comment 7 errata-xmlrpc 2026-06-23 18:42:28 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:28385 https://access.redhat.com/errata/RHSA-2026:28385