CVE-2026-27727: mchange-commons-java: Remote Code Execution via JNDI Reference Resolution

Published Feb 25, 2026
·
Updated

Impact mchange-commons-java includes code that mirrors early implementations of JNDI functionality, including support for remote factoryClassLocation values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted jaxax.naming.Reference or serialized object, they can provoke the download and execution of malicious code.

Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to false, com.sun.jndi.ldap.object.trustURLCodebase. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened.

Patches Mirroring the JDK patch, mchange-commons-java's JNDI functionality is now gated by configuration parameters that default to restrictive values. Those parameters are documented here.

Workarounds No. Users should upgrade to mchange-commons-java >= 0.4.0. Earlier versions should be avoided on application CLASSPATHs.

References

c3p0, you little rascal — Hans-Martin Münch c3p0 documentation, security note c3p0 documentation, configuring security

Other sources

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote factoryClassLocation values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted jaxax.naming.Reference or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to false, com.sun.jndi.ldap.object.trustURLCodebase. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened. Mirroring the JDK patch, mchange-commons-java's JNDI functionality is gated by configuration parameters that default to restrictive values starting in version 0.4.0. No known workarounds are available. Versions prior to 0.4.0 should be avoided on application CLASSPATHs.

NVD

Affected Software

3 affected componentsFixes available
maven/mchange/mchange-commons-java<0.4.0
maven/com.mchange:mchange-commons-java<0.4.0
0.4.0
mchange Mchange Commons Java<0.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/com.mchange:mchange-commons-java to a version that resolves this vulnerability.

    Fixed in 0.4.0
  2. Upgrade

    Upgrade mchange-commons-java to a version that resolves this vulnerability.

    Fixed in >= 0.4.0
  3. Configuration

    Ensure mchange-commons-java is at version 0.4.0 or later so its JNDI functionality is gated by configuration parameters that default to restrictive values; avoid using versions prior to 0.4.0 on the application CLASSPATH.

    mchange-commons-java JNDI functionality gated configuration parameters (defaults to restrictive values starting in version 0.4.0) = default restrictive values
  4. Configuration

    Set the System property com.sun.jndi.ldap.object.trustURLCodebase to false (it defaults to false in the hardened JDK behavior) to disable trust of remote codebase in JNDI object reference resolution.

    JDK JNDI dereferencing (mirrored behavior) com.sun.jndi.ldap.object.trustURLCodebase = false

Event History

Feb 25, 2026
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionWeakness
Data Sourced
via Red Hat·05:04 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:25 PM
RemedyAffected Software
Advisory Published
via GitHub·06:20 PM
Data Sourced
via GitHub·06:20 PM
DescriptionWeaknessAffected Software
Oct 11, 58320
Event
via NVD·06:57 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27727?

CVE-2026-27727 is classified with a high severity due to its potential for remote code execution.

2

How do I fix CVE-2026-27727?

To fix CVE-2026-27727, upgrade to version 0.4.0 or later of mchange-commons-java.

3

What applications are affected by CVE-2026-27727?

CVE-2026-27727 affects applications utilizing mchange-commons-java versions prior to 0.4.0.

4

What are the potential consequences of exploiting CVE-2026-27727?

Exploiting CVE-2026-27727 may lead to unauthorized remote code execution in affected applications.

5

Is there a workaround for CVE-2026-27727 before applying the fix?

A recommended workaround for CVE-2026-27727 is to disable JNDI functionality if it is not strictly necessary.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203