THREAT OPS › Threat News › [GHSA] GHSA-h84g-69h7-mw6v (high) — mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
[GHSA] GHSA-h84g-69h7-mw6v (high) — mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
GHSA-h84g-69h7-mw6v Severity: high CVE: CVE-2026-55153
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
### Impact Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementation (`com.mchange.v2.naming.JavaBeanObjectFactory`) willing to construct objects of arbitrary classes and initialize "JavaBean"-style p
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-55153cve
- https://commons.apache.org/proper/commons-beanutils/url
- https://commons.apache.org/proper/commons-collections/url
- https://www.mchange.com/projects/c3p0/#security-noteurl
- https://www.mchange.com/projects/c3p0/#configuring_securityurl
Original source: https://github.com/advisories/GHSA-h84g-69h7-mw6v