CVE-2026-27727

EUVD-2026-8683
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to `false`, `com.sun.jndi.ldap.object.trustURLCodebase`. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened. Mirroring the JDK patch, mchange-commons-java's JNDI functionality is gated by configuration parameters that default to restrictive values starting in version 0.4.0. No known workarounds are available. Versions prior to 0.4.0 should be avoided on application CLASSPATHs.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 54.22%
Affected Products (NVD)
VendorProductVersion
mchangemchange_commons_java
𝑥
< 0.4.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11
commons-java ≤
𝑥
< *
ADP
Red HatRed Hat Build of Debezium 3.2
commons-java ≤
𝑥
< *
ADP
Red HatRed Hat JBoss Enterprise Application Platform 8.1
commons-java ≤
𝑥
< *
ADP
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
0:6.6.48-1.Final_redhat_00001.1.el8eap ≤
𝑥
< *
ADP
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
0:6.6.48-1.Final_redhat_00001.1.el9eap ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 8
0:4.4.25-1.el8sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 9
0:4.4.25-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:4.4.25-1.el9sat ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19 for RHEL 9
0:4.7.5-1.el9sat ≤
𝑥
< *
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
c3p0
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage