[Japanese]

JVNDB-2026-026849

Vulnerability in Cosminexus HTTP Server

Overview

Vulnerability(CVE-2026-49975) has been found in Cosminexus HTTP Server.
This vulnerability does not apply if HTTP/2 protocol is disabled.
CVSS Severity (What is CVSS?)

Affected Products


Hitachi, Ltd
  • Cosminexus HTTP Server Linux(x64) 11-70
  • Cosminexus HTTP Server Linux(x64) 11-50-01 - 11-50-41
  • Cosminexus HTTP Server Linux(x64) 11-20-23 - 11-20-41
  • Cosminexus HTTP Server Windows(x64) 11-50 - 11-50-41
  • Cosminexus HTTP Server Windows(x64) 11-20-22 - 11-20-41
  • uCosminexus Application Server Linux(x64) 11-30 - 11-70
  • uCosminexus Application Server Windows(x64) 11-30 - 11-70
  • uCosminexus Application Server-R Linux(x64) 11-30 - 11-70
  • uCosminexus Application Server-R Windows(x64) 11-30 - 11-70
  • uCosminexus Developer Linux(x64) 11-30 - 11-70
  • uCosminexus Developer Windows(x64) 11-30 - 11-70
  • uCosminexus Primary Server Base Linux(x64) 11-30 - 11-70
  • uCosminexus Primary Server Base Windows(x64) 11-30 - 11-70
  • uCosminexus Service Architect Linux(x64) 11-30 - 11-70
  • uCosminexus Service Architect Windows(x64) 11-30 - 11-70
  • uCosminexus Service Platform Linux(x64) 11-30 - 11-70
  • uCosminexus Service Platform Windows(x64) 11-30 - 11-70

Please refer to Vendor Information for more details.
Impact

Regarding the impact of the vulnerability, please refer to the vendor advisory.
Solution

Please refer to the 'Vendor Information' section for the official countermeasure and take appropriate action.
Vendor Information

Hitachi, Ltd
CWE (What is CWE?)

CVE (What is CVE?)

  1. CVE-2026-49975
References

Revision History

  • [2026/08/05]
      Web page was published