CVE-2026-71375

HIGHCVSS 7.4/10

Last modified

CVE-2026-71375 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18..

Description

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
HitachiCosminexus Component Container>= 11-70-01, < 11-70-03; >= 11-60, < 11-60-03; >= 11-50, <= 11-50-03; >= 11-40, <= 11-40-03; >= 11-30, <= 11-30-08; >= 11-20, < 11-20-10; >= 11-10, <= 11-10-11; >= 11-00, < 11-00-13; >= 09-87, < 09-87-10; >= 09-80, < 09-80-05; >= 09-70, < 09-70-28; >= 09-50, <= 09-50-22; >= 09-00, <= 09-00-18

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-71375?
Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
How severe is CVE-2026-71375?
CVE-2026-71375 has a CVSS score of 7.4/10 (HIGH severity).
How do I fix CVE-2026-71375?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-71375?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST