CVE-2026-27830
swaldman c3p0, Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11, Red Hat Build of Debezium 3.2 취약점
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execut...
- 대응 우선순위
- 점검
- CVSS
- 8.9
- EPSS
- 0.53% 백분위 42.1% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.02.26