AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-13127

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability affects Java applications that process PDF files, where JavaScript can manipulate the document's structure, leading to the invalidation of page objects. This results in application crashes when generating thumbnails, posing a significant risk to stability and user experience. Organizations utilizing Java for PDF processing should prioritize addressing this issue to mitigate potential disruptions.

CVE
CVE-2026-13127
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Java

Original NVD Description

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)