CVE-2019-5427XML Entity Expansion in C3p0

Severity
7.5HIGHNVD
EPSS
3.9%
top 11.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateJun 16

Description

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

NVDmchange/c3p0< 0.9.5.4
Debianmchange/c3p0< 0.9.1.2-10.1+1
CVEListV5mchange/c3p0before 0.9.5.4
NVDoracle/documaker12.6.012.6.6

Also affects: Fedora 29, 30

Patches

🔴Vulnerability Details

4
OSV
Billion laughs attack in c3p02019-04-23
GHSA
Billion laughs attack in c3p02019-04-23
CVEList
CVE-2019-5427: c3p0 version < 02019-04-22
OSV
CVE-2019-5427: c3p0 version < 02019-04-22

📋Vendor Advisories

5
Ubuntu
c3p0 vulnerability2025-06-16
Ubuntu
c3p0 vulnerability2022-02-22
Ubuntu
c3p0 vulnerability2022-02-21
Red Hat
c3p0: loading XML configuration leads to denial of service2019-04-17
Debian
CVE-2019-5427: c3p0 - c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading ...2019

💬Community

3
Bugzilla
CVE-2019-5427 c3p0: loading XML configuration leads to denial of service2019-05-14
Bugzilla
CVE-2019-5427 c3p0: loading XML configuration leads to denial of service [fedora-all]2019-05-14
Bugzilla
CVE-2019-5427 c3p0: loading XML configuration leads to denial of service [epel-7]2019-05-14