Mchange maintains a focused library footprint centered on connection pooling (c3p0) and Java utilities (mchange-commons-java) that are embedded in Java applications, with recurring vulnerabilities concentrated in output injection and XML parsing contexts such as improper entity reference handling and external entity expansion. The exposure signature reflects the parsing and serialization complexity inherent to these utility libraries, where flaws can propagate to any downstream application that depends on them. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mchange over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27727CRITICAL mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLoca | Feb 25, 2026 | 9.8 | 35 | NO | NO |
CVE-2018-20433CRITICAL c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. | Dec 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-5427HIGH c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configu | Apr 22, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mchange.
Media articles that mention a CVE ID that affects a product developed by Mchange — matched by CVE ID, not by vendor name.