Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-20433

31
FAUCET Score

CVE-2018-20433 describes an XML External Entity (XXE) vulnerability in c3p0 versions 0.9.5.2 and earlier, specifically within the extractXmlConfigFromInputStream function during initialization, affecting products like Debian c3p0 and mchange c3p0. This critical vulnerability (CVSS 9.8) allows unauthenticated attackers to remotely execute arbitrary code, access sensitive data, or cause denial of service with high impact on confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
0.9.5.2CPE matchmatch criteria
cpe:2.3:a:mchange:c3p0:0.9.5.2:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.59%
Probability of exploitation in next 30 days
EPSS Percentile
90.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0459 is in the 84th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.mchange:c3p0Fixed in: 0.9.5.3
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 14 (Rocky)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat Satellite 5Fixed in: c3p0
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: rhevm-dependencies
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: c3p0
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: c3p0

Vendor Advisories (2)

mavenGHSA-q485-j897-qc27critical

XML External Entity Reference in mchange:c3p0

Jan 7, 2019
redhatCVE-2018-20433Moderate

c3p0: XML external entity processing in extractXmlConfigFromInputStream

Dec 20, 2018

References

github.com / zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2018/12/msg00021.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4