CVE-2026-71374 PUBLISHED

Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container

Assigner: Hitachi
Reserved: 06.08.2026 Published: 08.09.2026 Updated: 08.09.2026

Deserialization of untrusted data vulnerability in Cosminexus Component Container.

This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hitachi
Product Cosminexus Component Container
Versions Default: unaffected
  • affected from 11-70-01 to 11-70-03 (excl.)
  • affected from 11-60 to 11-60-03 (excl.)
  • affected from 11-50 to 11-50-03 (incl.)
  • affected from 11-40 to 11-40-03 (incl.)
  • affected from 11-30 to 11-30-08 (incl.)
  • affected from 11-20 to 11-20-10 (excl.)
  • affected from 11-10 to 11-10-11 (incl.)
  • affected from 11-00 to 11-00-13 (excl.)
  • affected from 09-87 to 09-87-10 (excl.)
  • affected from 09-80 to 09-80-05 (excl.)
  • affected from 09-70 to 09-70-28 (excl.)
  • affected from 09-50 to 09-50-22 (incl.)
  • affected from 09-00 to 09-00-18 (incl.)

References

Problem Types

  • CWE-502 Deserialization of untrusted data CWE

Impacts

  • CAPEC-586 Object Injection