Description
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free defect (CWE‑416) that allows JavaScript in a PDF to rewrite the page structure, invalidating page objects while the thumbnails still reference them, resulting in a crash. While the advisory title states the defect can be exploited for remote code execution, the official description only documents a crash; therefore the potential for arbitrary code execution remains unconfirmed but is a documented concern.

Affected Systems

Foxit Software Inc.’s Foxit PDF Editor and Foxit PDF Reader are impacted. The advisory does not list specific vulnerable versions, so any installed instance of these products could be at risk until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% shows a very low probability of widespread exploitation in the near term. This vulnerability is not listed in CISA’s KEV catalog. An attacker can embed malicious JavaScript in a crafted PDF and prompt a user to open it; when the PDF is processed, the use‑after‑free condition will be triggered, causing a crash.

Generated by OpenCVE AI on July 29, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Foxit PDF Editor and Foxit PDF Reader patches as soon as they become available to fix the use‑after‑free defect.
  • Disable or limit JavaScript execution in Foxit preferences to mitigate the memory corruption until an official fix is released.
  • Avoid opening PDF files from untrusted sources and consider processing PDFs in a sandboxed or virtualised environment to contain potential exploitation.

Generated by OpenCVE AI on July 29, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
Title Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:13:59.482Z

Reserved: 2026-06-24T03:01:48.781Z

Link: CVE-2026-13127

cve-icon Vulnrichment

Updated: 2026-07-08T12:13:55.481Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses