<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:49:09.220414+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10880</id>
    <title>bdu:2026-10880</title>
    <updated>2026-10-04T03:49:09.549212+00:00</updated>
    <content>bdu:2026-10880</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10880"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</id>
    <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T03:49:09.549298+00:00</updated>
    <content>certfr-2026-avi-0933</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368448</id>
    <title>EUVD-2026-368448</title>
    <updated>2026-10-04T03:49:09.549331+00:00</updated>
    <content>EUVD-2026-368448</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27830</id>
    <title>fkie_cve-2026-27830</title>
    <updated>2026-10-04T03:49:09.549351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&lt;String,Map&lt;String,String&gt;&gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects "indirectly serialized" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27830"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5476-xc4j-rqcv</id>
    <title>GHSA-5476-xc4j-rqcv — c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property</title>
    <updated>2026-10-04T03:49:09.549421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.mchange:c3p0</p>
<p>### Impact</p>
<p>c3p0 is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&lt;String,Map&lt;String,String&gt;&gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`.</p>
<p>The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects "indirectly serialized" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`.</p>
<p>Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, repr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5476-xc4j-rqcv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1691</id>
    <title>OESA-2026-1691 — c3p0 security update</title>
    <updated>2026-10-04T03:49:09.549512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: c3p0, openEuler:24.03-LTS-SP2: c3p0, openEuler:24.03-LTS-SP3: c3p0, openEuler:20.03-LTS-SP4: c3p0, openEuler:22.03-LTS-SP4: c3p0, openEuler:24.03-LTS: c3p0</p>
<p>c3p0 is a JDBC driver for extending traditional libraries (DriverManager-based libraries) with JNDI bindable data sources (including data sources), as described in the jdbc3 specification and jdbc2 standard extensions. They implement connections and statement pools.

Security Fix(es):</p>
<p>c3p0 is a JDBC connection pooling library. Prior to version 0.12.0, several `ConnectionPoolDataSource` implementations had a property called `userOverridesAsString`, which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;` but was maintained as a hex-encoded Java serialized object. An attacker able to reset this property on an existing `ConnectionPoolDataSource`, or via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances, could trigger deserialization. Combined with vulnerabilities in its main dependency, mchange-commons-java, which includes code mirroring early JNDI implementations with ungated support for remote `factoryClassLocation` values, attackers could set c3p0&amp;apos;s `userOverridesAsString` to hex-encoded serialized objects that include objects &amp;quot;indirectly serialized&amp;quot; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke the download and execution of malicious code from a remote `factoryClassLocation`, leading to arbitrary code execution on the application&amp;apos;s `CLASSPATH`.(CVE-2026-27830)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:18054</id>
    <title>RHSA-2026:18054 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.6 security update</title>
    <updated>2026-10-04T03:49:09.549584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons minimatch: minimatch: Denial of Service via specially crafted glob patterns org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:18054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0855-1</id>
    <title>SUSE-SU-2026:0855-1 — Security update for c3p0 and mchange-commons</title>
    <updated>2026-10-04T03:49:09.549662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for c3p0 and mchange-commons</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0855-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27830</id>
    <title>UBUNTU-CVE-2026-27830</title>
    <updated>2026-10-04T03:49:09.549694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: c3p0, Ubuntu:Pro:20.04:LTS: c3p0, Ubuntu:25.10: c3p0</p>
<p>c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&lt;String,Map&lt;String,String&gt;&gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects "indirectly serialized" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27830"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0694</id>
    <title>WID-SEC-W-2026-0694 — Red Hat Build of Debezium for Red Hat Application Foundations: Mehrere Schwachstellen ermöglichen Codeausführung</title>
    <updated>2026-10-04T03:49:09.549775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Build of Debezium for Red Hat Application Foundations ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0694"/>
  </entry>
</feed>
