CVE-2026-27830
swaldman c3p0, Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11, Red Hat Build of Debezium 3.2
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execut...
- CVSS
- 8.9
- EPSS
- 0.53% 42.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.26