C3p0
This hub aggregates every CVE we track for C3p0, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
1
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting C3p0.
- CVE-2026-55223c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
- CVE-2026-27830c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property8.0
- CVE-2019-5427c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.7.5
- CVE-2018-20433c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.9.8
Product normalization is registry-driven with AI assist and human review. How it works