AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-13129

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in Java allows an attacker to exploit a flaw in the handling of PDF files, specifically through JavaScript manipulation of the damaged field tree, leading to invalid form object access. This results in application crashes due to dereferencing an invalid pointer, which could be leveraged for denial-of-service attacks. Organizations utilizing Java for applications that process PDF files should prioritize patching this vulnerability to mitigate potential disruptions.

CVE
CVE-2026-13129
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Java

Original NVD Description

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.

Related CVEs

Other vulnerabilities affecting the same vendor(s)