{"id":"CVE-2018-20433","aliases":["GHSA-q485-j897-qc27"],"url":"https://o3.security/vulnerability/CVE-2018-20433","summary":"XML External Entity Reference in mchange:c3p0","details":"c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.","published":"2018-12-24T13:29:00.210Z","modified":"2026-08-07T14:31:33.491471Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.mchange:c3p0","fixedVersion":"0.9.5.3"}],"fix":{"url":"https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b","label":"zhutougg/c3p0@2eb0ea9"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQ47OFV57Y2DAHMGA5H3JOL4WHRWRFN4/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/12/msg00021.html"},{"type":"FIX","url":"https://github.com/zhutougg/c3p0/commit/2eb0ea97f745740b18dd45e4a909112d4685f87b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:31:33.491471Z"}}