USN-8642-1: c3p0 vulnerabilities
It was discovered that c3p0 was vulnerable to remote code execution via maliciously crafted serialized objects and JNDI references. An attacker could use this to execute arbitrary code, bypass security restrictions, or cause a denial of service.
CSIRTS triage
- What
- c3p0 is vulnerable to remote code execution via maliciously crafted serialized objects and JNDI references.
- Who is affected
- Applications using c3p0 connection pooling library that deserialize untrusted data.
- Urgency
- Critical; remote code execution is exploitable without authentication and can bypass security restrictions or cause denial of service.
- Action
- Update c3p0 to a patched version addressing CVE-2026-55223, CVE-2026-55153, CVE-2026-27830, and CVE-2026-27727.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch c3p0
Get an email when a new c3p0 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8642-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-552230.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-551530.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-278300.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-277270.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55223 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55153 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27830 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-27727 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highGHSA-h84g-69h7-mw6v: mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deser…ghsa
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Red Hat Build of Debezium for Red Hat Application Foundations: Multiple vulnerabilities allow …cert-bund
- mediumGHSA-w6w4-rjh9-9r58: c3p0 can, in combination with other libraries, compose to a "sink" for deserialization ga…ghsa
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund
- highCVE-2026-55153: mchange-commons-java is a Java library of shared utility classes used by mchange projects like…nvd
- unknownCVE-2026-55223: c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination wi…nvd
More from Ubuntu Security Notices
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25
- unknownUSN-8658-3: Linux kernel vulnerabilities2026-08-25
- unknownUSN-8643-4: Linux kernel vulnerabilities2026-08-25