Bug 2442908 (CVE-2026-27830) - CVE-2026-27830 c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects
Summary: CVE-2026-27830 c3p0: c3p0: Arbitrary Code Execution via deserialization of cr...
Keywords:
Status: NEW
Alias: CVE-2026-27830
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-26 01:02 UTC by OSIDB Bzimport
Modified: 2026-08-05 13:54 UTC (History)
66 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:18054 0 None None None 2026-05-18 12:21:57 UTC
Red Hat Product Errata RHSA-2026:18055 0 None None None 2026-05-18 12:19:02 UTC
Red Hat Product Errata RHSA-2026:18059 0 None None None 2026-05-18 12:12:27 UTC
Red Hat Product Errata RHSA-2026:28385 0 None None None 2026-06-23 18:42:32 UTC
Red Hat Product Errata RHSA-2026:3890 0 None None None 2026-03-05 13:32:58 UTC

Description OSIDB Bzimport 2026-02-26 01:02:21 UTC
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects "indirectly serialized" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, represents a serious independent fragility. The `userOverridesAsString` property of c3p0 `ConnectionPoolDataSource` classes has been reimplemented to use a safe CSV-based format, rather than rely upon potentially dangerous Java object deserialization. c3p0-0.12.0+ and above depend upon mchange-commons-java 0.4.0+, which gates support for remote `factoryClassLocation` values by configuration parameters that default to restrictive values. c3p0 additionally enforces the new mchange-commons-java `com.mchange.v2.naming.nameGuardClassName` to prevent injection of unexpected, potentially remote JNDI names. There is no supported workaround for versions of c3p0 prior to 0.12.0.

Comment 2 errata-xmlrpc 2026-03-05 13:32:54 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11

Via RHSA-2026:3890 https://access.redhat.com/errata/RHSA-2026:3890

Comment 3 errata-xmlrpc 2026-05-18 12:12:24 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:18059 https://access.redhat.com/errata/RHSA-2026:18059

Comment 4 errata-xmlrpc 2026-05-18 12:18:59 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:18055 https://access.redhat.com/errata/RHSA-2026:18055

Comment 5 errata-xmlrpc 2026-05-18 12:21:53 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:18054 https://access.redhat.com/errata/RHSA-2026:18054

Comment 7 errata-xmlrpc 2026-06-23 18:42:28 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:28385 https://access.redhat.com/errata/RHSA-2026:28385


Note You need to log in before you can comment on or make changes to this bug.