The c3p0 library, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. This vulnerability allows attackers to execute unexpected code on the application's CLASSPATH. The vulnerability was mitigated in c3p0 version 0.12.0, which changed the `userOverridesAsString` property to use a safe CSV-based format. Users of [truncated]
The CVE-2026-27727 vulnerability is a high-severity issue in the mchange-commons-java library, which provides Java utilities. The vulnerability is caused by the library's implementation of JNDI functionality, which allows for the download and execution of malicious code. This can be exploited by an attacker who can provoke an application to read a maliciously crafted `javax.naming.Reference` or serialized [truncated]