AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57256

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability in Java allows an application to crash when it opens a PDF containing JavaScript that manipulates list box fields, due to inadequate validation of form objects and their internal pointers. This can lead to unauthorized access and instability within the application. Organizations using Java for PDF processing should prioritize addressing this issue to mitigate potential disruptions and security risks.

CVE
CVE-2026-57256
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Java

Original NVD Description

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)