CVE-2026-55223 with a CVSS score of 6.3 is a vulnerability in the c3p0 library, which can be exploited by attackers to read arbitrary files via deserialization gadgets when combined with other libraries that compose to a "sink". The flaw type is CWE-502 and it affects versions prior to 0.14.0. Attackers require a susceptible JDBC DataSource or ConnectionPoolDataSource available on the application CLASSPATH, along with a susceptible JDBC driver, and a carrier that will automatically look up JavaBean properties on deserialization. In practice, the most common such carrier is the composition of a collection and a Comparator implementation that sorts based on JavaBean properties from Apache commons-beanutils. If an attacker can smuggle a malicious DataSource object in serialized form to a location from which an application will deserialize it, an attack is triggered. The business impact is significant as this vulnerability can lead to unauthorized data access and potential data breaches.
We recommend you to update c3p0 to version 0.14.0.[/subscribe_to_unlock_form]
CVE-2026-55223 with a CVSS score of 6.3 is a vulnerability in the c3p0 library, which can be exploited by attackers to read arbitrary files via deserialization gadgets when combined with other libraries that compose to a "sink". The flaw type is CWE-502 and it affects versions prior to 0.14.0. Attackers require a susceptible JDBC DataSource or ConnectionPoolDataSource available on the application CLASSPATH, along with a susceptible JDBC driver, and a carrier that will automatically look up JavaBean properties on deserialization. In practice, the most common such carrier is the composition of a collection and a Comparator implementation that sorts based on JavaBean properties from Apache commons-beanutils. If an attacker can smuggle a malicious DataSource object in serialized form to a location from which an application will deserialize it, an attack is triggered. The business impact is significant as this vulnerability can lead to unauthorized data access and potential data breaches.
We recommend you to update c3p0 to version 0.14.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]