CVE-2026-71374: Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container
Deserialization of untrusted data vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient. Exploitation has low attack complexity and requires neither prior privileges nor user interaction.
Which deployments should be checked for exposure?
Check all Cosminexus Component Container deployments running 11-70-01 before 11-70-03; 11-60 before 11-60-03; 11-50 through 11-50-03; 11-40 through 11-40-03; 11-30 through 11-30-08; 11-20 before 11-20-10; 11-10 through 11-10-11; 11-00 before 11-00-13; 09-87 before 09-87-10; 09-80 before 09-80-05; 09-70 before 09-70-28; 09-50 through 09-50-22; or 09-00 through 09-00-18.
What is the potential impact if exploitation succeeds?
The issue is rated critical with a CVSS score of 9.8. Its vector assigns high impact to confidentiality, integrity, and availability.