CVE-2026-27727
Publication date 25 February 2026
Last updated 18 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to `false`, `com.sun.jndi.ldap.object.trustURLCodebase`. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened. Mirroring the JDK patch, mchange-commons-java's JNDI functionality is gated by configuration parameters that default to restrictive values starting in version 0.4.0. No known workarounds are available. Versions prior to 0.4.0 should be avoided on application CLASSPATHs.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| c3p0 | 26.04 LTS resolute |
Fixed 0.9.1.2-11ubuntu0.1
|
| 24.04 LTS noble |
Fixed 0.9.1.2-10ubuntu2.1
|
|
| 22.04 LTS jammy |
Fixed 0.9.1.2-10ubuntu1.1
|
|
| 20.04 LTS focal |
Fixed 0.9.1.2-10ubuntu0.20.04.1+esm1
|
|
| 18.04 LTS bionic |
Fixed 0.9.1.2-9+deb8u1ubuntu0.18.04.2
|
|
| 16.04 LTS xenial |
Fixed 0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm2
|
|
| 14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
Severity score breakdown
CVSS version:
Base score
8.9 · High
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Base score
8.3 · High
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8642-1
- c3p0 vulnerabilities
- 18 August 2026