CVE-2026-71374
Received
Received - Intake
Deserialization of Untrusted Data in Cosminexus Component Container
Vulnerability report for CVE-2026-71374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-08
Last updated on: 2026-09-08
Assigner: Hitachi, Ltd.
Description
Description
Deserialization of untrusted data vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hitachi | cosminexus_component_container | From 09-00 (inc) to 11-70 (inc) |
| hitachi | ucosminexus_developer | From 09-00 (inc) to 11-70 (inc) |
| hitachi | application_server | From 09-00 (inc) to 11-70 (inc) |
| hitachi | service_platform | From 09-00 (inc) to 11-70 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |