UBUNTU-CVE-2026-55153

Source
https://ubuntu.com/security/CVE-2026-55153
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55153.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-55153
Upstream
Downstream
Related
Published
2026-07-01T21:17:00Z
Modified
2026-08-18T22:02:09Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and initialize "JavaBean"-style properties, which for certain classes enables JNDI injection and "deserialization gadgets." Such initialization is unsafe for some classes: for example, setting the contentType property of a Swing JEditorPane to text/html and its text property to HTML containing a stylesheet will provoke an HTTP GET on an arbitrary URL, potentially from within a trusted security domain. The problem is aggravated by the library's ReferenceIndirector, through which malicious JNDI Reference objects can be smuggled in for dereferencing wherever an application reads a Java-serialized object. This has been resolved in version 0.6.0.

References

Affected packages

Ubuntu:Pro:16.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm2

Affected versions

0.*
0.9.1.2-9
0.9.1.2-9+deb8u1build0.16.04.1
0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libc3p0-java",
            "binary_version": "0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55153.json"

Ubuntu:Pro:20.04:LTS / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.1.2-10ubuntu0.20.04.1+esm1

Affected versions

0.*
0.9.1.2-10
0.9.1.2-10ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libc3p0-java",
            "binary_version": "0.9.1.2-10ubuntu0.20.04.1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55153.json"

Ubuntu:25.10 / c3p0

Package

Name
c3p0
Purl
pkg:deb/ubuntu/c3p0?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.9.1.2-10ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libc3p0-java",
            "binary_version": "0.9.1.2-10ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55153.json"