AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57238

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in Java allows an attacker to exploit a flaw in PDF handling, where JavaScript can delete form field objects leading to application crashes upon subsequent access attempts. This high-severity issue (CVSS 7.8) poses a significant risk to applications that process PDFs, making it critical for developers and security teams to prioritize patching and mitigation efforts to prevent potential denial-of-service attacks. Organizations utilizing Java for PDF processing should take immediate action to address this vulnerability.

CVE
CVE-2026-57238
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Java

Original NVD Description

After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)