Description
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw is triggered when JavaScript embedded in a PDF deletes the current page; scripts that run afterward continue to access properties of the now‑invalid document view, causing Foxit PDF Editor and Foxit PDF Reader to crash. The vulnerability is recognised as CWE‑416 and results in a denial‑of‑service impact rather than arbitrary code execution.

Affected Systems

Foxit Software Inc. distributes the vulnerable code in both Foxit PDF Editor and Foxit PDF Reader. All released versions prior to the vendor’s latest update are potentially impacted; the advisory does not provide specific version ranges.

Risk and Exploitability

The attack vector is inferred to be the delivery of a crafted PDF file containing malicious JavaScript; any user who opens the file is at risk. The CVSS score of 7.8 indicates high severity for a remote denial‑of‑service vulnerability delivered via such a file. The EPSS score is below 1 %, implying a very low but non‑zero exploitation likelihood at the time of analysis. The vulnerability is not listed in the CISA KEV catalog and no widespread exploitation has been confirmed.

Generated by OpenCVE AI on July 28, 2026 at 09:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Foxit PDF Editor and Foxit PDF Reader to the latest vendor‑released version that addresses the use‑after‑free issue.
  • Disable JavaScript execution in the PDF reader’s security settings to block the vulnerable code path.
  • Avoid opening PDF files from untrusted or unknown sources; filter or quarantine such documents before they reach the reader.

Generated by OpenCVE AI on July 28, 2026 at 09:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
Title Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:14:25.870Z

Reserved: 2026-06-24T03:01:51.769Z

Link: CVE-2026-13128

cve-icon Vulnrichment

Updated: 2026-07-08T12:14:21.384Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses