<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:07:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10880</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10880</link>
      <description>bdu:2026-10880</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10880</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</link>
      <description>certfr-2026-avi-0933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</guid>
    </item>
    <item>
      <title>EUVD-2026-368448</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368448</link>
      <description>EUVD-2026-368448</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368448</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27830</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27830</link>
      <description>&lt;p&gt;c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27830</guid>
    </item>
    <item>
      <title>GHSA-5476-xc4j-rqcv — c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5476-xc4j-rqcv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.mchange:c3p0&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;c3p0 is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`.&lt;/p&gt;
&lt;p&gt;The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`.&lt;/p&gt;
&lt;p&gt;Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, repr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.mchange:c3p0&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;c3p0 is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`.&lt;/p&gt;
&lt;p&gt;The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`.&lt;/p&gt;
&lt;p&gt;Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, repr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5476-xc4j-rqcv</guid>
    </item>
    <item>
      <title>OESA-2026-1691 — c3p0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1691</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: c3p0, openEuler:24.03-LTS-SP2: c3p0, openEuler:24.03-LTS-SP3: c3p0, openEuler:20.03-LTS-SP4: c3p0, openEuler:22.03-LTS-SP4: c3p0, openEuler:24.03-LTS: c3p0&lt;/p&gt;
&lt;p&gt;c3p0 is a JDBC driver for extending traditional libraries (DriverManager-based libraries) with JNDI bindable data sources (including data sources), as described in the jdbc3 specification and jdbc2 standard extensions. They implement connections and statement pools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;c3p0 is a JDBC connection pooling library. Prior to version 0.12.0, several `ConnectionPoolDataSource` implementations had a property called `userOverridesAsString`, which conceptually represents a `Map&amp;amp;lt;String,Map&amp;amp;lt;String,String&amp;amp;gt;&amp;amp;gt;` but was maintained as a hex-encoded Java serialized object. An attacker able to reset this property on an existing `ConnectionPoolDataSource`, or via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances, could trigger deserialization. Combined with vulnerabilities in its main dependency, mchange-commons-java, which includes code mirroring early JNDI implementations with ungated support for remote `factoryClassLocation` values, attackers could set c3p0&amp;amp;apos;s `userOverridesAsString` to hex-encoded serialized objects that include objects &amp;amp;quot;indirectly serialized&amp;amp;quot; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke the download and execution of malicious code from a remote `factoryClassLocation`, leading to arbitrary code execution on the application&amp;amp;apos;s `CLASSPATH`.(CVE-2026-27830)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: c3p0, openEuler:24.03-LTS-SP2: c3p0, openEuler:24.03-LTS-SP3: c3p0, openEuler:20.03-LTS-SP4: c3p0, openEuler:22.03-LTS-SP4: c3p0, openEuler:24.03-LTS: c3p0&lt;/p&gt;
&lt;p&gt;c3p0 is a JDBC driver for extending traditional libraries (DriverManager-based libraries) with JNDI bindable data sources (including data sources), as described in the jdbc3 specification and jdbc2 standard extensions. They implement connections and statement pools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;c3p0 is a JDBC connection pooling library. Prior to version 0.12.0, several `ConnectionPoolDataSource` implementations had a property called `userOverridesAsString`, which conceptually represents a `Map&amp;amp;lt;String,Map&amp;amp;lt;String,String&amp;amp;gt;&amp;amp;gt;` but was maintained as a hex-encoded Java serialized object. An attacker able to reset this property on an existing `ConnectionPoolDataSource`, or via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances, could trigger deserialization. Combined with vulnerabilities in its main dependency, mchange-commons-java, which includes code mirroring early JNDI implementations with ungated support for remote `factoryClassLocation` values, attackers could set c3p0&amp;amp;apos;s `userOverridesAsString` to hex-encoded serialized objects that include objects &amp;amp;quot;indirectly serialized&amp;amp;quot; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke the download and execution of malicious code from a remote `factoryClassLocation`, leading to arbitrary code execution on the application&amp;amp;apos;s `CLASSPATH`.(CVE-2026-27830)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1691</guid>
    </item>
    <item>
      <title>RHSA-2026:18054 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.6 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:18054</link>
      <description>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons minimatch: minimatch: Denial of Service via specially crafted glob patterns org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons minimatch: minimatch: Denial of Service via specially crafted glob patterns org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:18054</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0855-1 — Security update for c3p0 and mchange-commons</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0855-1</link>
      <description>&lt;p&gt;Security update for c3p0 and mchange-commons&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for c3p0 and mchange-commons&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0855-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-27830</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27830</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: c3p0, Ubuntu:Pro:20.04:LTS: c3p0, Ubuntu:25.10: c3p0&lt;/p&gt;
&lt;p&gt;c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: c3p0, Ubuntu:Pro:20.04:LTS: c3p0, Ubuntu:25.10: c3p0&lt;/p&gt;
&lt;p&gt;c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map&amp;lt;String,Map&amp;lt;String,String&amp;gt;&amp;gt;`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application&amp;#39;s `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0&amp;#39;s main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0&amp;#39;s `userOverridesAsString` hex-encoded serialized objects that include objects &amp;#34;indirectly serialized&amp;#34; via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0&amp;#39;s vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27830</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0694 — Red Hat Build of Debezium for Red Hat Application Foundations: Mehrere Schwachstellen ermöglichen Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0694</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Build of Debezium for Red Hat Application Foundations ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Build of Debezium for Red Hat Application Foundations ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0694</guid>
    </item>
  </channel>
</rss>
