Junglewise Threat Intelligence

CVE-2026-55223: swaldman c3p0 deserialization gadget sink in DataSource properties

CVE-2026-55223 · Severity: medium · CVSS 4 · Published 2026-06-30

Technologies: com.mchange:c3p0 (Maven), Swaldman C3p0. Vendors: Maven.

Executive brief

c3p0 is a library used by Java applications to manage database connections. In versions prior to 0.14.0, it contains a flaw that allows it to be used as a 'sink' in a deserialization attack. If an attacker can send specially crafted data to an application that uses c3p0 alongside other specific libraries, they could potentially trigger unauthorized actions or compromise the server. This risk is higher if the application also uses older versions of Java or certain common utility libraries like Apache Commons BeanUtils.

Technical details

The vulnerability stems from c3p0's implementation of the JDBC DataSource and ConnectionPoolDataSource interfaces. Because methods like getConnection() follow the JavaBean 'getXXX' naming convention, they are treated as properties by introspection libraries. An attacker can craft a malicious serialized object that, when deserialized by an application using a 'carrier' library (like Apache Commons BeanUtils), triggers these methods. If a vulnerable JDBC driver is also present on the classpath, this can lead to an exploit. The fix in version 0.14.0 introduces explicit BeanInfo classes that exclude these sensitive methods from introspection, preventing them from being called during automated property lookups.

Affected products

  • swaldman c3p0 < 0.14.0

Timeline

  • 2026-06-11: disclosed: Advisory published by vendor
  • 2026-06-11: patched: Version 0.14.0 released
  • 2026-06-30: advisory: NVD published CVE-2026-55223

References

Related threats