Executive brief
c3p0 is a library used by Java applications to manage database connections. In versions prior to 0.14.0, it contains a flaw that allows it to be used as a 'sink' in a deserialization attack. If an attacker can send specially crafted data to an application that uses c3p0 alongside other specific libraries, they could potentially trigger unauthorized actions or compromise the server. This risk is higher if the application also uses older versions of Java or certain common utility libraries like Apache Commons BeanUtils.
Technical details
The vulnerability stems from c3p0's implementation of the JDBC DataSource and ConnectionPoolDataSource interfaces. Because methods like getConnection() follow the JavaBean 'getXXX' naming convention, they are treated as properties by introspection libraries. An attacker can craft a malicious serialized object that, when deserialized by an application using a 'carrier' library (like Apache Commons BeanUtils), triggers these methods. If a vulnerable JDBC driver is also present on the classpath, this can lead to an exploit. The fix in version 0.14.0 introduces explicit BeanInfo classes that exclude these sensitive methods from introspection, preventing them from being called during automated property lookups.
Affected products
- swaldman c3p0 < 0.14.0
Timeline
- 2026-06-11: disclosed: Advisory published by vendor
- 2026-06-11: patched: Version 0.14.0 released
- 2026-06-30: advisory: NVD published CVE-2026-55223