CVE-2026-71375: XXE Vulnerability in Cosminexus Component Container
Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-70-03 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-60-03 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-50-03 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-40-03 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-30-08 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-20-10 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-10-11 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 11-00-13 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 09-87-10 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 09-80-05 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 09-70-28 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 09-50-22 - Upgrade
Upgrade
Cosminexus Component Containerto a version that resolves this vulnerability.Fixed in 09-00-18
Event History
Frequently Asked Questions
Which releases need to be remediated?
Affected releases are 11-70-01 through before 11-70-03; 11-60 through before 11-60-03; 11-50 through 11-50-03; 11-40 through 11-40-03; 11-30 through 11-30-08; 11-20 through before 11-20-10; 11-10 through 11-10-11; 11-00 through before 11-00-13; 09-87 through before 09-87-10; 09-80 through before 09-80-05; 09-70 through before 09-70-28; 09-50 through 09-50-22; and 09-00 through 09-00-18.
Does exploiting this issue require authentication or user interaction?
No. The provided severity vector indicates network-based exploitation with no privileges required and no user interaction required, although attack complexity is rated high.
What impact can successful exploitation have?
The severity vector indicates high confidentiality and availability impact, with no integrity impact indicated.